Multiple Logic Issues in Apple Products Affecting iOS, iPadOS, and More
CVE-2020-9910

8.8HIGH

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
16 October 2020

Summary

Apple has addressed multiple logic issues in its products that could potentially allow a malicious attacker with arbitrary read and write capabilities to bypass Pointer Authentication. This could lead to unauthorized access and exploitation of system resources. Ensuring that devices are updated to the latest versions—such as iOS 13.6 and iPadOS 13.6, among others—is crucial to maintaining security and protecting sensitive information.

Affected Version(s)

iCloud for Windows < unspecified

iCloud for Windows (Legacy) < unspecified

iOS < unspecified

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.