CVE-2020-9802 describes a logic issue in Apple products, including iOS, iPadOS, tvOS, watchOS, Safari, iTunes for Windows, and iCloud for Windows. This vulnerability, rated 8.8 HIGH, allows for arbitrary code execution when processing maliciously crafted web content, requiring user interaction. While not listed in CISA KEV, its high EPSS and FAUCET Risk Score indicate significant potential for exploitation, and it has garnered community discussion and media coverage, including its association with the LightSpy iOS malware.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.19CPE matchmatch criteria | cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:* | ||
>= 11.0, < 11.2CPE matchmatch criteria | cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:* | ||
< 12.10.7CPE matchmatch criteria | cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:* | ||
< 13.1.1CPE matchmatch criteria | cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:* | ||
< 13.5CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.