CVE-2020-9907
KEVmassMemory Corruption with Kernel Privileges in Apple iOS, iPadOS, and tvOS
CISA: Apple Multiple Products Memory Corruption Vulnerability
Apple patched a kernel memory corruption flaw (CWE-787, out-of-bounds write) in iOS 13.6, iPadOS 13.6, and tvOS 13.4.8 by removing the vulnerable code. The flaw is triggered locally: an application running on the device (local attack vector, user interaction required per the CVSS scoring) can corrupt kernel memory and execute arbitrary code with kernel privileges. A successful attacker gains the highest privilege level on the device, effectively escalating from an application to full kernel control. Anyone running an iPhone, iPad, or Apple TV on versions earlier than iOS/iPadOS 13.6 or tvOS 13.4.8 is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-06-27, indicating exploitation in the wild, though no public proof-of-concept is known and EPSS estimates a roughly 3.9% chance of exploitation in the next 30 days.
What to do: Upgrade iPhones and iPads to iOS/iPadOS 13.6 or later and Apple TV devices to tvOS 13.4.8 or later, per CISA's required action to apply vendor updates. Because the KEV listing confirms in-the-wild exploitation, prioritize patching and check current builds via Settings > General > Software Update. On unpatched devices, limit exposure by only installing trusted applications, since triggering the flaw requires an application running locally on the device.
| Apple iPhone OS (iOS) | versions prior to iOS 13.6 |
| Apple iPadOS | versions prior to iPadOS 13.6 |
| Apple tvOS | versions prior to tvOS 13.4.8 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, tvos
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H