CVE-2020-9926Use After Free in Apple IOS AND Ipados

CWE-416Use After Free7 documents4 sources
Severity
7.8HIGHNVD
EPSS
0.7%
top 28.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 2
Latest updateMay 24

Description

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, iCloud for Windows 7.20, macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages8 packages

NVDapple/tvos< 13.4.8
CVEListV5apple/macosunspecified10.15+3
NVDapple/icloud< 7.20
NVDapple/ipados< 13.6
NVDapple/watchos< 6.2.8

🔴Vulnerability Details

2
GHSA
GHSA-q59g-53fj-p9fq: A use after free issue was addressed with improved memory management2022-05-24
CVEList
CVE-2020-9926: A use after free issue was addressed with improved memory management2021-04-02

📋Vendor Advisories

4
Apple
CVE-2020-9926: watchOS 6.2.82020-07-15
Apple
CVE-2020-9926: tvOS 13.4.82020-07-15
Apple
CVE-2020-9926: macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra2020-07-15
Apple
CVE-2020-9926: iOS 13.6 and iPadOS 13.62020-07-15
CVE-2020-9926 — Use After Free in Apple IOS AND Ipados | cvebase