Out-of-Bounds Write Vulnerability in Apple Products
CVE-2020-9871

7.8HIGH

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
22 October 2020

Summary

An out-of-bounds write vulnerability has been identified in several Apple products, which could be exploited through the processing of maliciously crafted images. If successfully attacked, this flaw may allow an attacker to execute arbitrary code on the affected device, leading to potential unauthorized access or control over the system. Apple has responded to this issue by implementing improved bounds checking measures, effectively mitigating the risk in new software updates across their platforms.

Affected Version(s)

iCloud for Windows < unspecified

iCloud for Windows (Legacy) < unspecified

iOS < unspecified

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.