CVE-2020-9996Use After Free in Apple IOS AND Ipados

CWE-416Use After Free4 documents4 sources
Severity
7.8HIGHNVD
EPSS
0.3%
top 45.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 8
Latest updateMay 24

Description

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A malicious application may be able to elevate privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5apple/macosunspecified11.0
NVDapple/ipados< 14.0
NVDapple/mac_os_x< 11.0.1
CVEListV5apple/ios_and_ipadosunspecified14.0
NVDapple/iphone_os< 14.0

🔴Vulnerability Details

2
GHSA
GHSA-gc87-63xf-6cg3: A use after free issue was addressed with improved memory management2022-05-24
CVEList
CVE-2020-9996: A use after free issue was addressed with improved memory management2020-12-08

💬Community

1
Bugzilla
CVE-2020-12050 sqliteodbc: packaging vulnerability in sqliteODBC exposing to local privilege escalation to root2020-05-07
CVE-2020-9996 — Use After Free in Apple IOS AND Ipados | cvebase