CVE-2020-9859: Apple Multiple Products Code Execution Vulnerability
A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.5.1 and iPadOS 13.5.1, macOS Catalina 10.15.5 Supplemental Update, tvOS 13.4.6, watchOS 6.2.6. An application may be able to execute arbitrary code with kernel privileges.
Other sources
Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.
— CISA
Kernel. A memory consumption issue was addressed with improved memory handling.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
tvOSto a version that resolves this vulnerability.Fixed in 13.4.6 - Upgrade
Upgrade
Apple macOS Supplemental Updateto a version that resolves this vulnerability.Fixed in 10.15.5 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 6.2.6 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 13.5.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 13.5.1 - Upgrade
Upgrade
Apple iOSto a version that resolves this vulnerability.Fixed in 13.5.1 - Upgrade
Upgrade
Apple iPadOSto a version that resolves this vulnerability.Fixed in 13.5.1 - Upgrade
Upgrade
macOS Catalinato a version that resolves this vulnerability.Fixed in 10.15.5 - Upgrade
Upgrade
watchOSto a version that resolves this vulnerability.Fixed in 6.2.6
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-9859?
CVE-2020-9859 is a code execution vulnerability that allows an application to execute arbitrary code with kernel privileges in multiple Apple products.
Which Apple products are affected by CVE-2020-9859?
CVE-2020-9859 affects multiple Apple products including iOS, iPadOS, macOS, tvOS, and watchOS.
What is the severity of CVE-2020-9859?
The severity of CVE-2020-9859 is high, with a severity score of 7.8.
How can I fix CVE-2020-9859?
To fix CVE-2020-9859, update to the latest versions of iOS, iPadOS, macOS, tvOS, and watchOS as mentioned in the Apple support articles.
Where can I find more information about CVE-2020-9859?
You can find more information about CVE-2020-9859 on the official Apple support articles.