CVE-2020-9819 is a memory consumption vulnerability affecting Apple iOS, iPadOS, and watchOS, where processing a maliciously crafted mail message can lead to heap corruption. This medium-severity flaw (CVSS 4.3) requires user interaction (UI:R) and could result in a denial of service (A:L). It is actively exploited (KEV: Yes), though no public exploit code is available via Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered significant community and media attention, including a warning from the German government.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.5CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 12.4.7CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 13.0, < 13.5CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 5.3.7CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.2.5CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.