cbcvebase.
CVE-2020-9870
published 2020-10-16

CVE-2020-9870: A logic issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. An attacker with…

PriorityP180high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
2.00%
78.5th percentile
A logic issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8. An attacker with memory write capability may be able to bypass pointer authentication codes and run arbitrary code.

Affected

8 ranges
VendorProductVersion rangeFixed in
appleios>= unspecified < iOS 13.6 and iPadOS 13.6iOS 13.6 and iPadOS 13.6
appleipados< 13.613.6
appleiphone_os< 13.613.6
applemac_os_x< 10.15.610.15.6
applemacos>= unspecified < macOS Catalina 10.15.6macOS Catalina 10.15.6
applemacos_catalina_10.15.6_security_update_2020-004_mojave_security_update_2020-004
appletvos< 13.4.813.4.8
appletvos>= unspecified < tvOS 13.4.8tvOS 13.4.8

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2020-9870 affects the Clang compiler component; binaries compiled with vulnerable Clang versions on affected Apple platforms (iOS <13.6, iPadOS <13.6, macOS Catalina <10.15.6, tvOS <13.4.8) may not correctly enforce pointer authentication codes (PAC), allowing PAC bypass by an attacker with memory write capability.
  • Exploitation requires an attacker to already have memory write capability on the target; detection should focus on memory corruption primitives or write primitives being chained with code-reuse/PAC-bypass techniques on affected Apple ARM64e platforms.
  • ·The vulnerability is a compiler-level logic issue in Clang, not a runtime library or OS kernel bug per se — affected binaries must have been compiled with the vulnerable Clang toolchain shipped with Xcode for the impact to apply. Patching requires rebuilding affected binaries with a fixed Clang version included in the listed OS updates.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vulncheck8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.