CVE-2020-9819
KEVmassHeap Corruption in Mail Message Processing on Apple iOS, iPadOS, and watchOS
CISA: Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability
Apple patched a memory-handling flaw (CWE-787, out-of-bounds write) in the Mail component of iOS, iPadOS, and watchOS that can cause heap corruption when the device processes a maliciously crafted mail message. Triggering it requires user interaction — the user must receive and process the crafted message — and the CVSS 3.1 scoring indicates the direct impact is limited availability loss on the affected device. Affected devices are those running iOS or iPadOS versions before 13.5 (or iOS 12.x before 12.4.7) and watches running watchOS before 6.2.5 (or watchOS 5.x before 5.3.7). The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming it has been exploited in the wild, though no public proof-of-concept is known and whether ransomware operations used it is unknown.
What to do: Update iPhones and iPads to iOS 13.5 or iPadOS 13.5 (or iOS 12.4.7 on devices that cannot run iOS 13), and Apple Watches to watchOS 6.2.5 or watchOS 5.3.7. Because this flaw is in CISA's KEV catalog, treat patching as urgent and verify fleet compliance with these versions. As an interim measure, exercise caution with mail messages and attachments from untrusted senders.
| Apple iOS | iOS versions prior to 13.5 and iOS 12.x prior to 12.4.7 |
| Apple iPadOS | iPadOS versions prior to 13.5 |
| Apple watchOS | watchOS versions prior to 6.2.5 and watchOS 5.x prior to 5.3.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5, watchOS 5.3.7. Processing a maliciously crafted mail message may lead to heap corruption.
- Affected
- Apple iOS, iPadOS, and watchOS
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, watchos
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.