First published: Wed Jul 15 2020(Updated: )
An input validation issue existed in Bluetooth. This issue was addressed with improved input validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An attacker in a privileged network position may be able to perform denial of service attack using malformed Bluetooth packets.
Credit: Andy Davis NCC GroupAndy Davis NCC Group product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <13.6 | |
Apple iPhone OS | <13.6 | |
Apple tvOS | <13.4.8 | |
Apple tvOS | <13.4.8 | 13.4.8 |
Apple iOS | <13.6 | 13.6 |
Apple iPadOS | <13.6 | 13.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9914 is a vulnerability related to an input validation issue in Bluetooth on certain Apple devices.
CVE-2020-9914 affects Apple devices running iOS 13.6, iPadOS 13.6, and tvOS 13.4.8.
The details of the exploitation technique for CVE-2020-9914 have not been disclosed publicly.
To fix CVE-2020-9914, update your Apple device to iOS 13.6, iPadOS 13.6, or tvOS 13.4.8.
More information about CVE-2020-9914 can be found on Apple's support website using the following references: [link1](https://support.apple.com/en-us/HT211288) and [link2](https://support.apple.com/en-us/HT211290).