CVE-2020-9849 — Sensitive Information Exposure in Apple IOS AND Ipados
Severity
6.5MEDIUMNVD
EPSS
1.1%
top 22.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 8
Latest updateMay 24
Description
An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS 14.0. A remote attacker may be able to leak memory.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages10 packages
🔴Vulnerability Details
3GHSA▶
GHSA-45qj-m3fv-x87x: An information disclosure issue was addressed with improved state management↗2022-05-24
OSV▶
CVE-2020-9849: An information disclosure issue was addressed with improved state management↗2020-12-08
CVEList▶
CVE-2020-9849: An information disclosure issue was addressed with improved state management↗2020-12-08
📋Vendor Advisories
3💬Community
1Bugzilla▶
CVE-2019-9849 libreoffice: Remote resources protection module not applied to bullet graphics↗2019-08-05