First published: Wed Jul 15 2020(Updated: )
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges.
Credit: 08Tc3wBB ZecOps product-security@apple.com 08Tc3wBB ZecOps product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple tvOS | <13.4.8 | 13.4.8 |
Apple iPadOS | <13.6 | |
Apple iPhone OS | <13.6 | |
Apple tvOS | <13.4.8 | |
Apple iOS | <13.6 | 13.6 |
Apple iPadOS | <13.6 | 13.6 |
<13.6 | ||
<13.6 | ||
<13.4.8 | ||
Apple Multiple Products |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9907 is a memory corruption vulnerability in Apple iOS, iPadOS, and tvOS that could allow an application to execute code with kernel privileges.
Apple iOS, iPadOS, and tvOS, specifically versions up to but not including 13.6 for iOS and iPadOS, and up to but not including 13.4.8 for tvOS.
The severity of CVE-2020-9907 is high, as it allows an application to execute code with kernel privileges.
To fix CVE-2020-9907, update your Apple iOS, iPadOS, and tvOS to version 13.6 for iOS and iPadOS, and version 13.4.8 for tvOS.
You can find more information about CVE-2020-9907 on the Apple support website: [link](https://support.apple.com/en-us/HT211288).