cbcvebase.
CVE-2020-9819
published 2020-06-09

CVE-2020-9819: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS…

PriorityP276medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
2.18%
80.4th percentile
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption.

Affected

9 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < iOS 13.5 and iPadOS 13.5iOS 13.5 and iPadOS 13.5
appleios-1>= unspecified < iOS 12.4.7iOS 12.4.7
appleipados< 13.513.5
appleiphone_os< 12.4.712.4.7
appleiphone_os>= 13.0 < 13.513.5
applewatchos< 5.3.75.3.7
applewatchos>= 6.0.0 < 6.2.56.2.5
applewatchos>= unspecified < watchOS 6.2.5watchOS 6.2.5
applewatchos-1>= unspecified < watchOS 5.3.7watchOS 5.3.7

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2020-9819 is a heap overflow flaw originating from the MFMutableData interface in the MIME framework in iOS; MFMutableData does not handle errors from the ftruncate() system call
  • On iOS 13, the heap overflow vulnerability can be triggered without any user interaction (zero-click) via a specially crafted email; on iOS 12, the victim must click the email unless the attacker controls the mail server
  • Exploitation is delivered via a specially crafted email sent to the victim; successful exploitation grants attacker capability to leak, modify, or delete emails within the Mail app context
  • Exploitation in the wild was identified as early as January 2018 against iOS 11.2.2; targets included Fortune 500 employees, carrier executives, MSS providers, and journalists
  • CVE-2020-9819 has been exploited in the wild by a nation-state actor since at least January 2018; treat any anomalous Mail app activity (email leakage, modification, deletion) on unpatched iOS devices as a high-priority indicator
  • ·Exploitation grants only Mail app context (email leak/modify/delete); full device compromise requires a chained kernel vulnerability, which ZecOps suspects was used but had not yet been identified at time of disclosure
  • ·Apple disputed immediate risk at time of disclosure, stating the vulnerabilities alone are insufficient to bypass iPhone/iPad security protections and found no evidence of customer exploitation
  • ·The out-of-bounds write (CVE-2020-9818) requires an additional vulnerability enabling an arbitrary selector call to trigger remotely; CVE-2020-9819 alone does not provide remote code execution without the companion flaw

CVSS provenance

nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vulncheck4.3MEDIUM
cisa4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.