CVE-2020-9910
published 2020-10-16CVE-2020-9910: Multiple issues were addressed with improved logic. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8…
PriorityP181high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
2.19%
80.4th percentile
Multiple issues were addressed with improved logic. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | icloud | < 7.20 | 7.20 |
| apple | icloud | >= 11.0 < 11.3 | 11.3 |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 11.3 | iCloud for Windows 11.3 |
| apple | icloud_for_windows | >= unspecified < iCloud for Windows 7.20 | iCloud for Windows 7.20 |
| apple | ios | >= unspecified < iOS 13.6 and iPadOS 13.6 | iOS 13.6 and iPadOS 13.6 |
| apple | ios_13.6_and_ipados | — | — |
| apple | ipados | < 13.6 | 13.6 |
| apple | iphone_os | < 13.6 | 13.6 |
| apple | itunes | < 12.10.8 | 12.10.8 |
| apple | itunes_for_windows | >= unspecified < iTunes 12.10.8 for Windows | iTunes 12.10.8 for Windows |
| apple | safari | < 13.1.2 | 13.1.2 |
| apple | safari | — | — |
| apple | safari | >= unspecified < Safari 13.1.2 | Safari 13.1.2 |
| apple | tvos | < 13.4.8 | 13.4.8 |
| apple | tvos | — | — |
| apple | tvos | >= unspecified < tvOS 13.4.8 | tvOS 13.4.8 |
| apple | watchos | < 6.2.8 | 6.2.8 |
| apple | watchos | — | — |
| apple | watchos | >= unspecified < watchOS 6.2.8 | watchOS 6.2.8 |
Detection & IOCsextracted from sources · hover to see the quote
- ·CVE-2020-9910 is a WebKit Pointer Authentication bypass requiring a prerequisite of arbitrary read/write capability. No concrete IOCs (hashes, domains, IPs, signatures, etc.) are present in any of the provided sources. Detection should focus on exploitation chains that first achieve arbitrary read/write in a WebKit context. ↗
- ·The vulnerability resides in the WebKit component across iOS/iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, and iCloud for Windows 7.20. Any unpatched version of these products should be treated as at-risk. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vulncheck8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2020-9910: iOS 13.6 and iPadOS 13.6
vendor_apple·2020-07-15·CVSS 8.8
CVE-2020-9910 [HIGH] CVE-2020-9910: iOS 13.6 and iPadOS 13.6
Apple Security Update: About the security content of iOS 13.6 and iPadOS 13.6
Product: iOS 13.6 and iPadOS
Version: 13.6
CVE: CVE-2020-9910
Component: WebKit
Impact: A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication
Description: Multiple issues were addressed with improved logic.
Apple
CVE-2020-9910: tvOS 13.4.8
vendor_apple·2020-07-15·CVSS 8.8
CVE-2020-9910 [HIGH] CVE-2020-9910: tvOS 13.4.8
Apple Security Update: About the security content of tvOS 13.4.8
Product: tvOS
Version: 13.4.8
CVE: CVE-2020-9910
Component: WebKit
Impact: A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication
Description: Multiple issues were addressed with improved logic.
Apple
CVE-2020-9910: Safari 13.1.2
vendor_apple·2020-07-15·CVSS 8.8
CVE-2020-9910 [HIGH] CVE-2020-9910: Safari 13.1.2
Apple Security Update: About the security content of Safari 13.1.2
Product: Safari
Version: 13.1.2
CVE: CVE-2020-9910
Component: WebKit
Impact: A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication
Description: Multiple issues were addressed with improved logic.
Apple
CVE-2020-9910: watchOS 6.2.8
vendor_apple·2020-07-15·CVSS 8.8
CVE-2020-9910 [HIGH] CVE-2020-9910: watchOS 6.2.8
Apple Security Update: About the security content of watchOS 6.2.8
Product: watchOS
Version: 6.2.8
CVE: CVE-2020-9910
Component: WebKit
Impact: A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication
Description: Multiple issues were addressed with improved logic.
GHSA
GHSA-mhx4-5j7f-6rxc: Multiple issues were addressed with improved logic
ghsa_unreviewed·2022-05-24
CVE-2020-9910 [HIGH] CWE-287 GHSA-mhx4-5j7f-6rxc: Multiple issues were addressed with improved logic
Multiple issues were addressed with improved logic. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
Project0
JITSploitation II: Getting Read/Write - Project Zero
project_zero·2020-09-01·CVSS 8.8
CVE-2020-9802 [HIGH] JITSploitation II: Getting Read/Write - Project Zero
Posted by Samuel Groß, Project Zero
This three-part series highlights the technical challenges involved in finding and exploiting JavaScript engine vulnerabilities in modern web browsers and evaluates current exploit mitigation technologies. The exploited vulnerability, CVE-2020-9802, was fixed in iOS 13.5, while two of the mitigation bypasses, CVE-2020-9870 and CVE-2020-9910, were fixed in iOS 13.6.
This is the second part in a series about a Safari renderer exploit from a JIT bug. In Part 1, a vulnerability in the DFG JIT’s implementation of Common-Subexpression Elimination was discussed. The second part starts from the well-known addrof and fakeobj primitives and shows how stable, arbitrary memory read/write can be constructed from it. For that, the StructureID randomization mitiga
Project0
JITSploitation III: Subverting Control Flow - Project Zero
project_zero·2020-09-01·CVSS 8.8
CVE-2020-9802 [HIGH] JITSploitation III: Subverting Control Flow - Project Zero
Posted by Samuel Groß, Project Zero
This three-part series highlights the technical challenges involved in finding and exploiting JavaScript engine vulnerabilities in modern web browsers and evaluates current exploit mitigation technologies. The exploited vulnerability, CVE-2020-9802, was fixed in iOS 13.5, while two of the mitigation bypasses, CVE-2020-9870 and CVE-2020-9910, were fixed in iOS 13.6.
This post is third in a series about a Safari renderer exploit. Part 1 discussed a JIT compiler vulnerability in JSC and Part 2 showed how it could be turned into a reliable read/write primitive despite various mitigations. The purpose of this post is to provide an overview of the various code execution mitigations present in WebKit on iOS 13 and to discuss different approaches for bypas
Project0
JITSploitation I: A JIT Bug - Project Zero
project_zero·2020-09-01·CVSS 8.8
CVE-2020-9802 [HIGH] JITSploitation I: A JIT Bug - Project Zero
By Samuel Groß, Project Zero
This three-part series highlights the technical challenges involved in finding and exploiting JavaScript engine vulnerabilities in modern web browsers and evaluates current exploit mitigation technologies. The exploited vulnerability, CVE-2020-9802, was fixed in iOS 13.5, while two of the mitigation bypasses, CVE-2020-9870 and CVE-2020-9910, were fixed in iOS 13.6.
How might a browser renderer exploit look like in 2020? I set out to answer that question in January this year. Since it’s one of my favorite areas in computer science, I wanted to find a JIT compiler vulnerability, and I was especially interested in trying to find (new) types of vulnerabilities that my fuzzer would have a hard time finding.
As WebKit (on iOS and likely soon on ARM-powered ma
VulnCheck
Apple icloud Improper Authentication
vulncheck·2020·CVSS 8.8
CVE-2020-9910 [HIGH] Apple icloud Improper Authentication
Apple icloud Improper Authentication
Multiple issues were addressed with improved logic. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
Affected: Apple icloud
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.threatfabric.com/blogs/lightspy-implant-for-ios
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://support.apple.com/HT211288https://support.apple.com/HT211290https://support.apple.com/HT211291https://support.apple.com/HT211292https://support.apple.com/HT211293https://support.apple.com/HT211294https://support.apple.com/HT211295https://support.apple.com/HT211288https://support.apple.com/HT211290https://support.apple.com/HT211291https://support.apple.com/HT211292https://support.apple.com/HT211293https://support.apple.com/HT211294https://support.apple.com/HT211295
2020-10-16
Published
Exploited in the wild