First published: Mon May 18 2020(Updated: )
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. A malicious application may be able to determine another application's memory layout.
Credit: an anonymous researcher an anonymous researcher an anonymous researcher an anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple tvOS | <13.4.5 | 13.4.5 |
Apple watchOS | <6.2.5 | 6.2.5 |
Apple iOS | <13.5 | 13.5 |
Apple iPadOS | <13.5 | 13.5 |
Apple iPadOS | <13.5 | |
Apple iPhone OS | <13.5 | |
Apple Mac OS X | <10.15.5 | |
Apple tvOS | <13.4.5 | |
Apple watchOS | <6.2.5 | |
Apple macOS Catalina | <10.15.5 | 10.15.5 |
Apple Mojave | ||
Apple High Sierra |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9797 is a vulnerability in the Kernel that could lead to information disclosure.
WatchOS version up to but excluding 6.2.5, macOS Catalina version up to but excluding 10.15.5, iOS version up to but excluding 13.5, iPadOS version up to but excluding 13.5, and tvOS version up to but excluding 13.4.5 are affected by CVE-2020-9797.
To fix CVE-2020-9797, you should update your software to the recommended versions: watchOS 6.2.5, macOS Catalina 10.15.5, iOS 13.5, iPadOS 13.5, and tvOS 13.4.5.
You can find more information about CVE-2020-9797 on Apple's support page: [https://support.apple.com/en-us/HT211175](https://support.apple.com/en-us/HT211175).