ZeroHour

CVE-2020-27950

KEVmass

Kernel Memory Disclosure in Apple iOS, iPadOS, macOS, and watchOS

CISA: Apple Multiple Products Memory Initialization Vulnerability

CVSS 3.1
5.5 medium
EPSS
16%p97
Published
()
KEV added
AI analysis

CVE-2020-27950 is an improper memory initialization flaw (CWE-665) in the kernels of Apple's iOS, iPadOS, macOS, and watchOS, addressed in the November 2020 update round. It is triggered when a user runs a malicious application on a vulnerable device; because kernel memory is not properly initialized, the app can read leftover kernel data. A successful attacker gains disclosure of sensitive kernel memory, which can expose secrets or weaken kernel defenses, though the local, user-interaction-dependent attack path keeps the CVSS 3.1 score at a moderate 5.5. Affected populations include iPhone and iPad users on builds older than iOS/iPadOS 14.2 (or iOS 12.4.9 on legacy devices), Mac users on High Sierra, Mojave, Catalina, and early Big Sur, and Apple Watch users on older watchOS branches. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and related reporting ties the timeframe to the 'Coruna' iOS exploit kit attributed to an advanced, previously unidentified hacking group, indicating exploitation in the wild.

What to do: Update iPhones and iPads to iOS/iPadOS 14.2 (or iOS 12.4.9 for devices that cannot run newer branches), Macs to macOS Big Sur 11.0.1, the macOS Catalina 10.15.7 Supplemental Update, or Security Update 2020-006 for High Sierra/Mojave, and Apple Watches to watchOS 7.1, 6.2.9, or 5.3.9 per device generation. As a CISA KEV entry, federal and high-value environments should prioritize this patch and check for signs of malicious local applications on unpatched devices. There is no practical workaround because the flaw is in the kernel.

Affected
Apple iOS (iPhone OS)versions prior to iOS 14.2, and the legacy-device branch prior to iOS 12.4.9
Apple iPadOSversions prior to iPadOS 14.2
Apple macOSHigh Sierra and Mojave prior to Security Update 2020-006; Catalina prior to the 10.15.7 Update and 10.15.7 Supplemental Update; Big Sur prior to 11.0.1
Apple watchOSversions prior to watchOS 7.1, with older device branches fixed in watchOS 6.2.9 and watchOS 5.3.9
Estimated exposure
mass≈1.5 billion active devices across iPhone, iPad, Mac, and Apple Watch were running vulnerable OS builds at disclosure — Apple publicly reported roughly 1.5 billion active devices in early 2020, and the kernel flaw affected all devices running pre-patch versions of iOS, iPadOS, macOS, and watchOS, so the exposed base is effectively the entire active Apple…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, macos, watchos
Weakness
CWE-665
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news