CVE-2020-9819
published 2020-06-09CVE-2020-9819: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS…
PriorityP276medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
2.18%
80.4th percentile
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios | >= unspecified < iOS 13.5 and iPadOS 13.5 | iOS 13.5 and iPadOS 13.5 |
| apple | ios-1 | >= unspecified < iOS 12.4.7 | iOS 12.4.7 |
| apple | ipados | < 13.5 | 13.5 |
| apple | iphone_os | < 12.4.7 | 12.4.7 |
| apple | iphone_os | >= 13.0 < 13.5 | 13.5 |
| apple | watchos | < 5.3.7 | 5.3.7 |
| apple | watchos | >= 6.0.0 < 6.2.5 | 6.2.5 |
| apple | watchos | >= unspecified < watchOS 6.2.5 | watchOS 6.2.5 |
| apple | watchos-1 | >= unspecified < watchOS 5.3.7 | watchOS 5.3.7 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2020-9819 is a heap overflow flaw originating from the MFMutableData interface in the MIME framework in iOS; MFMutableData does not handle errors from the ftruncate() system call ↗
- →On iOS 13, the heap overflow vulnerability can be triggered without any user interaction (zero-click) via a specially crafted email; on iOS 12, the victim must click the email unless the attacker controls the mail server ↗
- →Exploitation is delivered via a specially crafted email sent to the victim; successful exploitation grants attacker capability to leak, modify, or delete emails within the Mail app context ↗
- →Exploitation in the wild was identified as early as January 2018 against iOS 11.2.2; targets included Fortune 500 employees, carrier executives, MSS providers, and journalists ↗
- →CVE-2020-9819 has been exploited in the wild by a nation-state actor since at least January 2018; treat any anomalous Mail app activity (email leakage, modification, deletion) on unpatched iOS devices as a high-priority indicator ↗
- ·Exploitation grants only Mail app context (email leak/modify/delete); full device compromise requires a chained kernel vulnerability, which ZecOps suspects was used but had not yet been identified at time of disclosure ↗
- ·Apple disputed immediate risk at time of disclosure, stating the vulnerabilities alone are insufficient to bypass iPhone/iPad security protections and found no evidence of customer exploitation ↗
- ·The out-of-bounds write (CVE-2020-9818) requires an additional vulnerability enabling an arbitrary selector call to trigger remotely; CVE-2020-9819 alone does not provide remote code execution without the companion flaw ↗
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vulncheck4.3MEDIUM
cisa4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x45r-8w3c-gwgc: A memory consumption issue was addressed with improved memory handling
ghsa_unreviewed·2022-05-24
CVE-2020-9819 [MEDIUM] CWE-119 GHSA-x45r-8w3c-gwgc: A memory consumption issue was addressed with improved memory handling
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption.
VulnCheck
Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
vulncheck·2020·CVSS 4.3
CVE-2020-9819 [MEDIUM] CWE-787 Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.
Affected: Apple iOS, iPadOS, and watchOS
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.tenable.com/blog/multiple-zero-day-vulnerabilities-in-ios-mail-app-exploited-in-the-wild; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-05-03
CISA
Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
cisa·2021-11-03·CVSS 4.3
CVE-2020-9819 [MEDIUM] CWE-787 Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
Vulnerability: Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
Affected: Apple iOS, iPadOS, and watchOS
Apple iOS, iPadOS, and watchOS Mail contains a memory corruption vulnerability that may allow heap corruption when processing a maliciously crafted mail message.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-9819
Remediation Due Date: 2022-05-03
No detection rules found.
No public exploits indexed.
Qualys
Expand Your Vulnerability & Patch Management Program to Mobile Devices with Qualys VMDR | Qualys
blogs_qualys·2021-02-10·CVSS 7.8
[HIGH] Expand Your Vulnerability & Patch Management Program to Mobile Devices with Qualys VMDR | Qualys
As mobile devices have become ubiquitous in almost every business process, whether in bank branches, manufacturing sites or retail stores, they are now hosting business applications and data that is subject to regulatory compliance and security. With access to critical corporate resources inside the corporate network, these mobile devices have become critical assets for the organization.
### Mobile Attack Surface Challenges
Alongside this trend, there has been a drastic rise in Android, iOS, and iPadOS vulnerabilities and an increased number of vulnerable apps distributed from authorized app stores. Through these vectors, mobile devices have become preferred targets for attackers to gain an entry point into corporate networks. Last year, for example, 900 million Apple iOS users were affe
Qualys
Expand Your Vulnerability & Patch Management Program to Mobile Devices with Qualys VMDR
blogs_qualys·2021-02-10·CVSS 7.8
[HIGH] Expand Your Vulnerability & Patch Management Program to Mobile Devices with Qualys VMDR
As mobile devices have become ubiquitous in almost every business process, whether in bank branches, manufacturing sites or retail stores, they are now hosting business applications and data that is subject to regulatory compliance and security. With access to critical corporate resources inside the corporate network, these mobile devices have become critical assets for the organization.
## Mobile Attack Surface Challenges
Alongside this trend, there has been a drastic rise in Android, iOS, and iPadOS vulnerabilities and an increased number of vulnerable apps distributed from authorized app stores. Through these vectors, mobile devices have become preferred targets for attackers to gain an entry point into corporate networks. Last year, for example, 900 million Apple iOS users were affec
Checkpoint
1st June – Threat Intelligence Bulletin
blogs_checkpoint·2020-06-01·CVSS 9.8
CVE-2019-10149 [CRITICAL] 1st June – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 1st June – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 1st June 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The US NSA has warned that Russia’s Sandworm APT group, an arm of Russian military intelligence, has been exploiting a vulnerability in the Exim mail traffic agent since August of last year, giving it remote code execution abilities. Sandworm is believed to have been responsible for the Ukraine grid disruptions in 2015.
C
Tenable
CVE-2020-9818, CVE-2020-9819: Multiple Zero-Day Vulnerabilities in iOS Mail App Exploited in the Wild
blogs_tenable·2020-04-22·CVSS 8.8
[HIGH] CVE-2020-9818, CVE-2020-9819: Multiple Zero-Day Vulnerabilities in iOS Mail App Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://support.apple.com/HT211168https://support.apple.com/HT211169https://support.apple.com/HT211175https://support.apple.com/HT211176https://support.apple.com/HT211168https://support.apple.com/HT211169https://support.apple.com/HT211175https://support.apple.com/HT211176https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9819
2020-06-09
Published
2021-11-03
Added to CISA KEV
Exploited in the wild