ZeroHour

CVE-2020-9859

KEVmass

Double-Free Kernel Flaw Allows Code Execution on Apple iOS, macOS, tvOS, watchOS

CISA: Apple Multiple Products Code Execution Vulnerability

CVSS 3.1
7.8 high
EPSS
<1%p56
Published
()
KEV added
AI analysis

CVE-2020-9859 is a memory handling flaw in the kernels of Apple's operating systems (classified as CWE-415, a double free), addressed through improved memory handling by Apple. It is triggered by an application running on the device, and the local attack vector requires no user interaction. A successful exploit allows arbitrary code execution with kernel privileges, giving the attacker near-complete control of the affected device. Users of iPhone (iOS), iPad (iPadOS), Macs running macOS Catalina 10.15, Apple TV (tvOS), and Apple Watch (watchOS) on versions prior to the fixes are affected. The flaw was reported as a zero-day fixed by Apple and is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and it is associated in public reporting with the unc0ver jailbreak, though no public proof-of-concept is known.

What to do: Update to iOS/iPadOS 13.5.1 or later, apply the macOS Catalina 10.15.5 Supplemental Update, and update Apple TV (tvOS 13.4.6 or later) and Apple Watch (watchOS 6.2.6 or later), per the vendor's instructions as required by CISA KEV. Because this is a local privilege escalation, prioritize patching fleet devices where untrusted apps may run, and check for devices unable to upgrade (older iPhones/iPads, Apple TVs and watches stuck on pre-fix versions) as residual risk.

Affected
Apple iPhone OS (iOS)versions prior to iOS 13.5.1
Apple iPadOSversions prior to iPadOS 13.5.1
Apple macOS (macOS Catalina 10.15)versions prior to macOS Catalina 10.15.5 Supplemental Update
Apple tvOSversions prior to tvOS 13.4.6
Apple watchOSversions prior to watchOS 6.2.6
Estimated exposure
masshundreds of millions of Apple devices (iPhone, iPad, Mac, Apple TV, Apple Watch install base at the time of disclosure) — Apple's combined active-device install base publicly exceeded one billion units in 2020, and the affected iOS/iPadOS/macOS versions were widely deployed before the May/June 2020 updates, so the order of magnitude is derived from device…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, mac os x, tvos, watchos
Weakness
CWE-415
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news