First published: Wed Jul 15 2020(Updated: )
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. Processing a maliciously crafted audio file may lead to arbitrary code execution.
Credit: JunDong Xie Xingwei Lin AntJunDong Xie Xingwei Lin AntJunDong Xie Xingwei Lin AntJunDong Xie XingWei Lin AntJunDong Xie XingWei Lin AntJunDong Xie XingWei Lin AntJunDong Xie XingWei Lin AntJunDong Xie XingWei Lin AntJunDong Xie XingWei Lin AntJunDong Xie XingWei Lin AntJunDong Xie XingWei Lin AntJunDong Xie XingWei Lin Ant product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <13.6 | 13.6 |
Apple iPadOS | <13.6 | 13.6 |
Apple watchOS | <6.2.8 | 6.2.8 |
Apple iPadOS | <13.6 | |
Apple iPhone OS | <13.6 | |
Apple Mac OS X | <10.15.6 | |
Apple tvOS | <13.4.8 | |
Apple watchOS | <6.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9888 is a vulnerability related to audio in macOS, iOS, iPadOS, watchOS, and tvOS.
CVE-2020-9888 affects Apple devices running macOS Catalina 10.15.6, Mojave, High Sierra, iOS up to 13.6, iPadOS up to 13.6, watchOS up to 6.2.8, and tvOS up to 13.4.8.
The severity of CVE-2020-9888 is not specified in the provided information.
To fix CVE-2020-9888, update your Apple device to the latest version of macOS, iOS, iPadOS, watchOS, or tvOS, depending on the affected operating system.
You can find more information about CVE-2020-9888 on the Apple support website using the provided references.