CVE-2020-9859 is a memory consumption vulnerability affecting Apple's iOS, iPadOS, macOS, tvOS, and watchOS. This flaw, categorized as CWE-415, could allow an application to execute arbitrary code with kernel privileges. With a CVSS score of 7.8 (High), it represents a significant risk where a local attacker can achieve high impact on confidentiality, integrity, and availability with low attack complexity. Notably, this vulnerability has been actively exploited in the wild, specifically associated with the "unc0ver" jailbreak, and received considerable media and community attention. Apple addressed this issue with improved memory handling in iOS 13.5.1, iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, and watchOS 6.2.6.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.5.1CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 13.5.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.15.5CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 13.4.6CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 6.2.6CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.