CVE-2020-9891 is an out-of-bounds read vulnerability affecting Apple's iOS, iPadOS, macOS, tvOS, and watchOS. It carries a high CVSS score of 7.8, indicating that processing a maliciously crafted audio file could lead to arbitrary code execution with high impact on confidentiality, integrity, and availability, requiring user interaction. While no public exploit intelligence like Metasploit or ExploitDB entries exist, and it's not on the KEV catalog, the vulnerability has received some community discussion and media coverage. This issue was patched in iOS 13.6, iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, and watchOS 6.2.8.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.6CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 13.6CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.15.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 13.4.8CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 6.2.8CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.