CVE-2020-9818 is an out-of-bounds write vulnerability affecting Apple iOS, iPadOS, and watchOS, specifically within the Mail application. This critical flaw, with a CVSS score of 8.8 (HIGH), allows an unauthenticated attacker to achieve unexpected memory modification or application termination by sending a maliciously crafted email, requiring user interaction. The vulnerability is actively exploited in the wild, as indicated by its presence in the KEV catalog, despite a lack of public exploit code on platforms like Metasploit or ExploitDB. Community discussion and media coverage, including a warning from the German government, highlight the urgency of patching this issue, which Apple addressed in iOS 13.5, iPadOS 13.5, iOS 12.4.7, and watchOS 6.2.5.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.5CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 12.4.7CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.5CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 6.2.5CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.