Out-of-Bounds Read Vulnerability in Apple iOS and macOS Products
CVE-2020-9984

7.8HIGH

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
22 October 2020

What is CVE-2020-9984?

An out-of-bounds read vulnerability was identified in Apple products, enabling attackers to exploit improper input validation when processing maliciously crafted images. This can potentially lead to arbitrary code execution on the affected devices, compromising user security. Apple has resolved this issue in the latest updates for iOS, iPadOS, macOS, tvOS, watchOS, iTunes, and iCloud for Windows. Users are advised to upgrade to the most recent versions to mitigate risks associated with this vulnerability.

Affected Version(s)

iCloud for Windows < unspecified

iCloud for Windows (Legacy) < unspecified

iOS < unspecified

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.