Apple Security Advisories · May 2020 — Apple Security Advisories
60 advisories 60 CVEs 2 EXPLOITED

Apple-vendor CVEs for 2020-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 2 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2020-9802

iPadOSExploitedVulnCheck KEV listedCRITICAL2020-05-26

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously cra...

CVEs:CVE-2020-9802

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9771

macOSExploitedVulnCheck KEV listedHIGH2020-05-27

This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A user may gain access to protected parts of the file system.

CVEs:CVE-2020-9771

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9850

iPadOSWeaponized exploitCRITICAL2020-05-26

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A remote attacker may be a...

CVEs:CVE-2020-9850

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9839

iPadOSWeaponized exploitHIGH2020-05-27

A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to gain elevated privileges.

CVEs:CVE-2020-9839

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9856

macOSWeaponized exploitMEDIUM2020-05-27

This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able to gain elevated privileges.

CVEs:CVE-2020-9856

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9801

SafariWeaponized exploitMEDIUM2020-05-27

A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1.1. A malicious process may cause Safari to launch an application.

CVEs:CVE-2020-9801

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple — —
Upstream advisory

CVE-2020-13630

OtherPoC exploitCRITICAL2020-05-27

ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.

CVEs:CVE-2020-13630

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-13434

OtherPoC exploitCRITICAL2020-05-24

SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.

CVEs:CVE-2020-13434

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-13631

OtherPoC exploitCRITICAL2020-05-27

SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.

CVEs:CVE-2020-13631

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
macos affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9789

iPadOSCoalition ESS < 30%HIGH2020-05-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19....

CVEs:CVE-2020-9789

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9790

iPadOSCoalition ESS < 30%HIGH2020-05-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19....

CVEs:CVE-2020-9790

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9793

iPadOSCoalition ESS < 30%HIGH2020-05-27

A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A remote attacker may be able to cause arbitrary code execution.

CVEs:CVE-2020-9793

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9806

iPadOSCoalition ESS < 30%CRITICAL2020-05-26

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing...

CVEs:CVE-2020-9806

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9807

iPadOSCoalition ESS < 30%CRITICAL2020-05-26

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing...

CVEs:CVE-2020-9807

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9803

iPadOSCoalition ESS < 30%CRITICAL2020-05-26

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing malic...

CVEs:CVE-2020-9803

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9844

iPadOSCoalition ESS < 30%CRITICAL2020-05-27

A double free issue was addressed with improved memory management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.

CVEs:CVE-2020-9844

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9800

iPadOSCoalition ESS < 30%CRITICAL2020-05-27

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing mal...

CVEs:CVE-2020-9800

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
mac_os_x affected apple — —
safari affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9827

iPadOSCoalition ESS < 30%HIGH2020-05-27

A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A remote attacker may be able to cause a denial of service.

CVEs:CVE-2020-9827

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9794

iPadOSCoalition ESS < 30%HIGH2020-05-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A mali...

CVEs:CVE-2020-9794

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9816

iPadOSCoalition ESS < 30%HIGH2020-05-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. Opening a maliciously crafted PDF file may lead to an unexpected application ...

CVEs:CVE-2020-9816

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9837

iPadOSCoalition ESS < 30%HIGH2020-05-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5. A remote attacker may be able to leak memory.

CVEs:CVE-2020-9837

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
Upstream advisory

CVE-2020-9791

iPadOSCoalition ESS < 30%HIGH2020-05-27

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. Processing a maliciously crafted audio file may lead to arbitrary code execution.

CVEs:CVE-2020-9791

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9815

iPadOSCoalition ESS < 30%HIGH2020-05-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. Processing a maliciously crafted audio file may lead to arbitrary code execution.

CVEs:CVE-2020-9815

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9813

iPadOSCoalition ESS < 30%HIGH2020-05-27

A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to execute...

CVEs:CVE-2020-9813

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9814

iPadOSCoalition ESS < 30%HIGH2020-05-27

A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to execute...

CVEs:CVE-2020-9814

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9821

iPadOSCoalition ESS < 30%HIGH2020-05-27

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to execute arbitrary code with kernel privi...

CVEs:CVE-2020-9821

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9852

iPadOSCoalition ESS < 30%HIGH2020-05-27

An integer overflow was addressed through improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-9852

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-3882

macOSCoalition ESS < 30%MEDIUM2020-05-27

This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. Importing a maliciously crafted calendar invitation may exfiltrate user information.

CVEs:CVE-2020-3882

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9822

macOSCoalition ESS < 30%HIGH2020-05-27

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-9822

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9834

macOSCoalition ESS < 30%HIGH2020-05-27

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.5. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-9834

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9826

iPadOSCoalition ESS < 30%HIGH2020-05-27

A denial of service issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A remote attacker may be able to cause a denial of service.

CVEs:CVE-2020-9826

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9841

macOSCoalition ESS < 30%HIGH2020-05-27

An integer overflow was addressed through improved input validation. This issue is fixed in macOS Catalina 10.15.5. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-9841

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9805

iPadOSCoalition ESS < 30%CRITICAL2020-05-26

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing maliciously cra...

CVEs:CVE-2020-9805

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9828

macOSCoalition ESS < 30%HIGH2020-05-27

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to leak sensitive user information.

CVEs:CVE-2020-9828

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9843

iPadOSCoalition ESS < 30%CRITICAL2020-05-26

An input validation issue was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Processing...

CVEs:CVE-2020-9843

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple — —
ipados affected apple — —
iphone_os affected apple — —
itunes affected apple — —
safari affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9817

macOSCoalition ESS < 30%HIGH2020-05-27

A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to gain root privileges.

CVEs:CVE-2020-9817

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9830

iPadOSCoalition ESS < 30%HIGH2020-05-27

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-9830

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9840

OtherCoalition ESS < 30%HIGH2020-05-11

In SwiftNIO Extras before 1.4.1, a logic issue was addressed with improved restrictions.

CVEs:CVE-2020-9840

Affected products

ProductStatusVendorPackageEcosystem
nioextras affected apple — —
Upstream advisory

CVE-2020-9842

iPadOSCoalition ESS < 30%HIGH2020-05-27

An entitlement parsing issue was addressed with improved parsing. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application could interact with system processes to access private inform...

CVEs:CVE-2020-9842

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9788

macOSCoalition ESS < 30%HIGH2020-05-27

A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.5. A file may be incorrectly rendered to execute JavaScript.

CVEs:CVE-2020-9788

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9809

iPadOSCoalition ESS < 30%HIGH2020-05-27

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to determine kernel memory layout.

CVEs:CVE-2020-9809

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9812

iPadOSCoalition ESS < 30%HIGH2020-05-27

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A local user may be able to read kernel memory.

CVEs:CVE-2020-9812

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9797

iPadOSCoalition ESS < 30%HIGH2020-05-27

An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to determine another application's m...

CVEs:CVE-2020-9797

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9824

macOSCoalition ESS < 30%HIGH2020-05-27

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. A non-privileged user may be able to modify restricted network settings.

CVEs:CVE-2020-9824

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9808

iPadOSCoalition ESS < 30%CRITICAL2020-05-27

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to cause unexpected system termination or write kern...

CVEs:CVE-2020-9808

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9811

iPadOSCoalition ESS < 30%MEDIUM2020-05-27

An information disclosure issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A local user may be able to read kernel memory.

CVEs:CVE-2020-9811

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9857

macOSCoalition ESS < 30%MEDIUM2020-05-27

An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.5, Security Update 2020-003 Mojave, Security Update 2020-003 High Sierra. A malicious website may be able to e...

CVEs:CVE-2020-9857

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-6616

OtherCoalition ESS < 30%MEDIUM2020-05-08

Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (PRNG) is used in situations where a Hardware Random Number Generator (HRNG) should have been used to prevent spoofing. This affects, ...

CVEs:CVE-2020-6616

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9831

macOSCoalition ESS < 30%MEDIUM2020-05-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to determine kernel memory layout.

CVEs:CVE-2020-9831

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9832

macOSCoalition ESS < 30%MEDIUM2020-05-27

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to determine kernel memory layout.

CVEs:CVE-2020-9832

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9825

iPadOSCoalition ESS < 30%HIGH2020-05-27

An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A malicious application may be able to bypass Privacy preferences.

CVEs:CVE-2020-9825

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9847

macOSCoalition ESS < 30%HIGH2020-05-27

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to break out of its sandbox.

CVEs:CVE-2020-9847

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9851

macOSCoalition ESS < 30%MEDIUM2020-05-27

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to modify protected parts of the file system.

CVEs:CVE-2020-9851

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9858

OtherCoalition ESS < 30%CRITICAL2020-05-27

A dynamic library loading issue was addressed with improved path searching. This issue is fixed in Windows Migration Assistant 2.2.0.0 (v. 1A11). Running the installer in an untrusted directory may result in arbitrary code execution.

CVEs:CVE-2020-9858

Affected products

ProductStatusVendorPackageEcosystem
windows_migration_assistant affected apple — —
Upstream advisory

CVE-2019-20807

OtherCoalition ESS < 30%CRITICAL2020-05-28

In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).

CVEs:CVE-2019-20807

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9772

iPadOSCoalition ESS < 30%MEDIUM2020-05-27

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A sandboxed process may be able to circumvent sandbox restrictions.

CVEs:CVE-2020-9772

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
tvos affected apple — —
watchos affected apple — —
Upstream advisory

CVE-2020-9804

macOSCoalition ESS < 30%MEDIUM2020-05-27

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.5. Inserting a USB device that sends invalid messages may cause a kernel panic.

CVEs:CVE-2020-9804

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9833

macOSCoalition ESS < 30%MEDIUM2020-05-27

A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.5. A local user may be able to read kernel memory.

CVEs:CVE-2020-9833

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9792

iPadOSCoalition ESS < 30%HIGH2020-05-27

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. A USB device may be able to cause a denial of service.

CVEs:CVE-2020-9792

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple — —
iphone_os affected apple — —
mac_os_x affected apple — —
Upstream advisory

CVE-2020-9855

macOSCoalition ESS < 30%HIGH2020-05-27

A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Catalina 10.15.5. A local attacker may be able to elevate their privileges.

CVEs:CVE-2020-9855

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple — —
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.