cbcvebase.
CVE-2020-9859
published 2020-06-05

CVE-2020-9859: A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.

Affected

9 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < iOS 13.5.1 and iPadOS 13.5.1iOS 13.5.1 and iPadOS 13.5.1
appleipados< 13.5.113.5.1
appleiphone_os< 13.5.113.5.1
applemac_os_x< 10.15.510.15.5
applemacos>= unspecified < macOS Catalina 10.15.5 Supplemental UpdatemacOS Catalina 10.15.5 Supplemental Update
appletvos< 13.4.613.4.6
appletvos>= unspecified < tvOS 13.4.6tvOS 13.4.6
applewatchos< 6.2.66.2.6
applewatchos>= unspecified < watchOS 6.2.6watchOS 6.2.6

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH