Out-of-Bounds Read in Apple Products Due to Input Validation Flaw
CVE-2020-9938

7.8HIGH

Key Information:

Vendor
Apple
Status
Vendor
CVE Published:
22 October 2020

Summary

A security vulnerability has been identified in various Apple operating systems and applications, leading to potential arbitrary code execution when processing specially crafted images. This issue arises due to inadequate input validation, which could be exploited by an attacker through the manipulation of image files. Users are advised to update to the latest versions to mitigate the risk associated with this vulnerability.

Affected Version(s)

iCloud for Windows < unspecified

iCloud for Windows (Legacy) < unspecified

iOS < unspecified

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.