ZeroHour

CVE-2020-9819

KEVmass

Heap Corruption in Mail Message Processing on Apple iOS, iPadOS, and watchOS

CISA: Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability

CVSS 3.1
4.3 medium
EPSS
2%p81
Published
()
KEV added
AI analysis

Apple patched a memory-handling flaw (CWE-787, out-of-bounds write) in the Mail component of iOS, iPadOS, and watchOS that can cause heap corruption when the device processes a maliciously crafted mail message. Triggering it requires user interaction — the user must receive and process the crafted message — and the CVSS 3.1 scoring indicates the direct impact is limited availability loss on the affected device. Affected devices are those running iOS or iPadOS versions before 13.5 (or iOS 12.x before 12.4.7) and watches running watchOS before 6.2.5 (or watchOS 5.x before 5.3.7). The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming it has been exploited in the wild, though no public proof-of-concept is known and whether ransomware operations used it is unknown.

What to do: Update iPhones and iPads to iOS 13.5 or iPadOS 13.5 (or iOS 12.4.7 on devices that cannot run iOS 13), and Apple Watches to watchOS 6.2.5 or watchOS 5.3.7. Because this flaw is in CISA's KEV catalog, treat patching as urgent and verify fleet compliance with these versions. As an interim measure, exercise caution with mail messages and attachments from untrusted senders.

Affected
Apple iOSiOS versions prior to 13.5 and iOS 12.x prior to 12.4.7
Apple iPadOSiPadOS versions prior to 13.5
Apple watchOSwatchOS versions prior to 6.2.5 and watchOS 5.x prior to 5.3.7
Estimated exposure
masshundreds of millions of Apple devices (iPhone/iPad/Apple Watch installed base on vulnerable iOS 12/13, iPadOS, or watchOS 5/6 builds) — Apple's active device installed base exceeds one billion units and iOS 12/13 plus watchOS 5/6 covered the large majority of active devices when the May 2020 fixes shipped, so the vulnerable population is plausibly in the hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption.

CISA Known Exploited Vulnerability
Affected
Apple iOS, iPadOS, and watchOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, watchos
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.