ZeroHour

CVE-2020-3837

KEVmass

Memory Corruption in Apple iOS, macOS, tvOS, watchOS Enables Kernel-Level Code Execution

CISA: Apple Multiple Products Memory Corruption Vulnerability

CVSS 3.1
7.8 high
EPSS
16%p97
Published
()
KEV added
AI analysis

Apple patched an out-of-bounds write (CWE-787), a memory corruption flaw in kernel memory handling, across iOS/iPadOS, macOS Catalina, tvOS and watchOS. The flaw is triggered by a local application performing the faulty memory access, and the CVSS vector indicates user interaction (running the application) is required. A successful attacker can execute arbitrary code with kernel privileges, meaning full compromise of the affected device. Anyone running iPhone/iPad, Mac, Apple TV or Apple Watch software older than iOS/iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1 and watchOS 6.1.2 respectively is affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), so exploitation has been observed in the wild, and EPSS assigns a 16.1% probability of exploitation within 30 days (97th percentile).

What to do: Update all Apple endpoints to the fixed releases: iOS and iPadOS 13.3.1 or later, macOS Catalina 10.15.3 or later, tvOS 13.3.1 or later, and watchOS 6.1.2 or later; apply per vendor instructions to satisfy the KEV required action. Inventory managed and BYOD Apple devices for OS versions below these builds and prioritize patching, since the flaw is KEV-listed and mobile spyware campaigns targeting iPhones are active (e.g., LightSpy, though no confirmed link to this CVE is in the data). Until devices are patched, limit installing applications from untrusted sources, as triggering requires running a local application.

Affected
Apple iPhone OS (iOS)versions prior to iOS 13.3.1
Apple iPadOSversions prior to iPadOS 13.3.1
Apple macOS (Catalina)versions prior to macOS Catalina 10.15.3
Apple tvOSversions prior to tvOS 13.3.1
Apple watchOSversions prior to watchOS 6.1.2
Estimated exposure
masswell over 1 billion active Apple devices in the affected installed base (iPhone/iPad/Mac/Apple TV/Apple Watch) — Apple's publicly reported active-device installed base exceeds a billion units, and at the time of the January 2020 fix the large majority of those devices were running builds older than the patched versions, though the share still…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, mac os x, tvos, watchos
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news