cbcvebase.
CVE-2020-9910
published 2020-10-16

CVE-2020-9910: Multiple issues were addressed with improved logic. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8…

PriorityP181high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
2.19%
80.4th percentile
Multiple issues were addressed with improved logic. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, iCloud for Windows 7.20. A malicious attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

Affected

19 ranges
VendorProductVersion rangeFixed in
appleicloud< 7.207.20
appleicloud>= 11.0 < 11.311.3
appleicloud_for_windows>= unspecified < iCloud for Windows 11.3iCloud for Windows 11.3
appleicloud_for_windows>= unspecified < iCloud for Windows 7.20iCloud for Windows 7.20
appleios>= unspecified < iOS 13.6 and iPadOS 13.6iOS 13.6 and iPadOS 13.6
appleios_13.6_and_ipados
appleipados< 13.613.6
appleiphone_os< 13.613.6
appleitunes< 12.10.812.10.8
appleitunes_for_windows>= unspecified < iTunes 12.10.8 for WindowsiTunes 12.10.8 for Windows
applesafari< 13.1.213.1.2
applesafari
applesafari>= unspecified < Safari 13.1.2Safari 13.1.2
appletvos< 13.4.813.4.8
appletvos
appletvos>= unspecified < tvOS 13.4.8tvOS 13.4.8
applewatchos< 6.2.86.2.8
applewatchos
applewatchos>= unspecified < watchOS 6.2.8watchOS 6.2.8

Detection & IOCsextracted from sources · hover to see the quote

  • ·CVE-2020-9910 is a WebKit Pointer Authentication bypass requiring a prerequisite of arbitrary read/write capability. No concrete IOCs (hashes, domains, IPs, signatures, etc.) are present in any of the provided sources. Detection should focus on exploitation chains that first achieve arbitrary read/write in a WebKit context.
  • ·The vulnerability resides in the WebKit component across iOS/iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, and iCloud for Windows 7.20. Any unpatched version of these products should be treated as at-risk.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vulncheck8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.