CVE-2020-3837
KEVmassMemory Corruption in Apple iOS, macOS, tvOS, watchOS Enables Kernel-Level Code Execution
CISA: Apple Multiple Products Memory Corruption Vulnerability
Apple patched an out-of-bounds write (CWE-787), a memory corruption flaw in kernel memory handling, across iOS/iPadOS, macOS Catalina, tvOS and watchOS. The flaw is triggered by a local application performing the faulty memory access, and the CVSS vector indicates user interaction (running the application) is required. A successful attacker can execute arbitrary code with kernel privileges, meaning full compromise of the affected device. Anyone running iPhone/iPad, Mac, Apple TV or Apple Watch software older than iOS/iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1 and watchOS 6.1.2 respectively is affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), so exploitation has been observed in the wild, and EPSS assigns a 16.1% probability of exploitation within 30 days (97th percentile).
What to do: Update all Apple endpoints to the fixed releases: iOS and iPadOS 13.3.1 or later, macOS Catalina 10.15.3 or later, tvOS 13.3.1 or later, and watchOS 6.1.2 or later; apply per vendor instructions to satisfy the KEV required action. Inventory managed and BYOD Apple devices for OS versions below these builds and prioritize patching, since the flaw is KEV-listed and mobile spyware campaigns targeting iPhones are active (e.g., LightSpy, though no confirmed link to this CVE is in the data). Until devices are patched, limit installing applications from untrusted sources, as triggering requires running a local application.
| Apple iPhone OS (iOS) | versions prior to iOS 13.3.1 |
| Apple iPadOS | versions prior to iPadOS 13.3.1 |
| Apple macOS (Catalina) | versions prior to macOS Catalina 10.15.3 |
| Apple tvOS | versions prior to tvOS 13.3.1 |
| Apple watchOS | versions prior to watchOS 6.1.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, mac os x, tvos, watchos
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H