ZeroHour

CVE-2020-9818

KEVmass

Out-of-Bounds Write in Apple iOS, iPadOS, and watchOS Mail Message Processing

CISA: Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability

CVSS 3.1
8.8 high
EPSS
2%p82
Published
()
KEV added
AI analysis

CVE-2020-9818 is an out-of-bounds write vulnerability (CWE-787) in the mail handling components of Apple iOS, iPadOS, and watchOS, caused by insufficient bounds checking. An attacker can trigger the flaw by sending a maliciously crafted email message that the device processes, requiring user interaction but no privileges or authentication beyond message delivery. Successful processing of the crafted message can cause unexpected memory modification or termination of the affected application, with the CVSS 3.1 score of 8.8 reflecting potentially high confidentiality, integrity, and availability impact. All users of iPhones and iPads running iOS/iPadOS versions before 13.5 (or iOS 12.x before 12.4.7) and Apple Watches running watchOS before 6.2.5 are affected. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog as of November 3, 2021, indicating confirmed in-the-wild exploitation, though no public proof-of-concept is known and ransomware use is unconfirmed.

What to do: Update iPhones and iPads to iOS/iPadOS 13.5 or later, or to iOS 12.4.7 or later for devices stuck on the iOS 12 branch, and update Apple Watches to watchOS 6.2.5 or later. Check fleet device OS versions via MDM or device settings to confirm no endpoints remain on vulnerable builds; there is no known workaround beyond patching, so treat inbound email processing on unpatched devices as an attack vector.

Affected
Apple iPhone OS (iOS)iOS versions prior to 13.5; iOS 12.x prior to 12.4.7
Apple iPadOSiPadOS versions prior to 13.5
Apple watchOSwatchOS versions prior to 6.2.5
Estimated exposure
masshundreds of millions of Apple devices (iPhone, iPad, and Apple Watch) were potentially exposed when the flaw shipped in iOS/iPadOS <13.5 and watchOS <6.2.5 — Apple's active installed base of iOS devices exceeds one billion units and watchOS ships on tens of millions of Apple Watches, so any vulnerability affecting all devices on unpatched OS versions reaches mass scale, though the number still…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5. Processing a maliciously crafted mail message may lead to unexpected memory modification or application termination.

CISA Known Exploited Vulnerability
Affected
Apple iOS, iPadOS, and watchOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, watchos
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.