Out-of-bounds Write Issue in Apple iOS, macOS, and iCloud Products
CVE-2020-9936
7.8HIGH
Summary
An out-of-bounds write flaw has been identified that occurs during the processing of specially crafted images, potentially allowing an attacker to execute arbitrary code. This critical issue has been rectified in recent updates including iOS 13.6, iPadOS 13.6, and other Apple products, which now feature enhanced bounds checking mechanisms. Users are strongly advised to update their devices to mitigate this risk.
Affected Version(s)
iCloud for Windows < unspecified
iCloud for Windows (Legacy) < unspecified
iOS < unspecified
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved