CVE-2020-9859
KEVmassDouble-Free Kernel Flaw Allows Code Execution on Apple iOS, macOS, tvOS, watchOS
CISA: Apple Multiple Products Code Execution Vulnerability
CVE-2020-9859 is a memory handling flaw in the kernels of Apple's operating systems (classified as CWE-415, a double free), addressed through improved memory handling by Apple. It is triggered by an application running on the device, and the local attack vector requires no user interaction. A successful exploit allows arbitrary code execution with kernel privileges, giving the attacker near-complete control of the affected device. Users of iPhone (iOS), iPad (iPadOS), Macs running macOS Catalina 10.15, Apple TV (tvOS), and Apple Watch (watchOS) on versions prior to the fixes are affected. The flaw was reported as a zero-day fixed by Apple and is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), and it is associated in public reporting with the unc0ver jailbreak, though no public proof-of-concept is known.
What to do: Update to iOS/iPadOS 13.5.1 or later, apply the macOS Catalina 10.15.5 Supplemental Update, and update Apple TV (tvOS 13.4.6 or later) and Apple Watch (watchOS 6.2.6 or later), per the vendor's instructions as required by CISA KEV. Because this is a local privilege escalation, prioritize patching fleet devices where untrusted apps may run, and check for devices unable to upgrade (older iPhones/iPads, Apple TVs and watches stuck on pre-fix versions) as residual risk.
| Apple iPhone OS (iOS) | versions prior to iOS 13.5.1 |
| Apple iPadOS | versions prior to iPadOS 13.5.1 |
| Apple macOS (macOS Catalina 10.15) | versions prior to macOS Catalina 10.15.5 Supplemental Update |
| Apple tvOS | versions prior to tvOS 13.4.6 |
| Apple watchOS | versions prior to watchOS 6.2.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, mac os x, tvos, watchos
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H