First published: Wed Jul 15 2020(Updated: )
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.
Credit: JunDong Xie XingWei Lin Ant product-security@apple.com Xingwei Lin Ant
Affected Software | Affected Version | How to fix |
---|---|---|
tvOS | <13.4.8 | 13.4.8 |
macOS Catalina | <10.15.6 | 10.15.6 |
macOS Mojave | ||
macOS High Sierra | ||
Apple iOS, iPadOS, and watchOS | <13.6 | 13.6 |
Apple iOS, iPadOS, and watchOS | <13.6 | 13.6 |
Apple iOS, iPadOS, and watchOS | <6.2.8 | 6.2.8 |
Apple iOS, iPadOS, and watchOS | <13.6 | |
iOS | <13.6 | |
Apple iOS and macOS | <10.15.6 | |
tvOS | <13.4.8 | |
Apple iOS, iPadOS, and watchOS | <6.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9888 is a vulnerability related to audio in macOS, iOS, iPadOS, watchOS, and tvOS.
CVE-2020-9888 affects Apple devices running macOS Catalina 10.15.6, Mojave, High Sierra, iOS up to 13.6, iPadOS up to 13.6, watchOS up to 6.2.8, and tvOS up to 13.4.8.
The severity of CVE-2020-9888 is not specified in the provided information.
To fix CVE-2020-9888, update your Apple device to the latest version of macOS, iOS, iPadOS, watchOS, or tvOS, depending on the affected operating system.
You can find more information about CVE-2020-9888 on the Apple support website using the provided references.