Out-of-Bounds Read in Apple Products Due to Input Validation Flaw
CVE-2020-9938

7.8HIGH

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
22 October 2020

What is CVE-2020-9938?

A security vulnerability has been identified in various Apple operating systems and applications, leading to potential arbitrary code execution when processing specially crafted images. This issue arises due to inadequate input validation, which could be exploited by an attacker through the manipulation of image files. Users are advised to update to the latest versions to mitigate the risk associated with this vulnerability.

Affected Version(s)

iCloud for Windows < unspecified

iCloud for Windows (Legacy) < unspecified

iOS < unspecified

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.