First published: Wed Jul 15 2020(Updated: )
WebKit. A use after free issue was addressed with improved memory management.
Credit: 0011 Trend Micro Zero Day InitiativeWen Xu SSLabGeorgia Tech 0011 Trend Micro Zero Day InitiativeWen Xu SSLabGeorgia Tech 0011 Trend Micro Zero Day InitiativeWen Xu SSLabGeorgia Tech 0011 Trend Micro Zero Day InitiativeWen Xu SSLabGeorgia Tech 0011 Trend Micro Zero Day InitiativeWen Xu SSLabGeorgia Tech 0011 Trend Micro Zero Day InitiativeWen Xu SSLabGeorgia Tech 0011 Trend Micro Zero Day InitiativeWen Xu SSLabGeorgia Tech 0011 Trend Micro Zero Day InitiativeWen Xu SSLabGeorgia Tech 0011 Trend Micro Zero Day InitiativeWen Xu SSLabGeorgia Tech product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/webkitgtk | <2.28.4 | 2.28.4 |
tvOS | <13.4.8 | 13.4.8 |
Apple iOS, iPadOS, and watchOS | <6.2.8 | 6.2.8 |
Apple iCloud | <11.3 | 11.3 |
Apple iCloud | <7.20 | 7.20 |
iTunes | <12.10.8 | 12.10.8 |
Safari | <13.1.2 | 13.1.2 |
Apple iOS and iPadOS | <13.6 | 13.6 |
Apple iOS, iPadOS, and macOS | <13.6 | 13.6 |
iCloud for Windows | <7.20 | |
iCloud for Windows | >=11.0<11.3 | |
iTunes | <12.10.8 | |
Safari | <13.1.2 | |
Apple iOS, iPadOS, and macOS | <13.6 | |
iPhone OS | <13.6 | |
tvOS | <13.4.8 | |
Apple iOS, iPadOS, and watchOS | <6.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-9895 is a use after free vulnerability in Apple Safari, iOS, iPadOS, watchOS, iCloud for Windows, tvOS, and iTunes for Windows.
CVE-2020-9895 allows an attacker to execute arbitrary code or cause a denial of service by exploiting the use after free vulnerability.
The severity of CVE-2020-9895 is high.
To fix CVE-2020-9895, update to the latest version of the affected software as recommended by Apple.
You can find more information about CVE-2020-9895 on the Apple support website.