First published: Wed Sep 16 2020(Updated: )
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0, macOS Big Sur 11.0.1. Processing a maliciously crafted image may lead to arbitrary code execution.
Credit: Mickey Jin Trend MicroXingwei Lin Ant Security LightMickey Jin Trend MicroXingwei Lin Ant Security LightMickey Jin Trend MicroXingwei Lin Ant Security LightMickey Jin Trend MicroXingwei Lin Ant Security Light product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iPadOS | <14.0 | |
Apple iPhone OS | <14.0 | |
Apple macOS | >=11.0<11.0.1 | |
Apple tvOS | <14.0 | |
Apple watchOS | <7.0 | |
Apple iOS | <14.0 | 14.0 |
Apple iPadOS | <14.0 | 14.0 |
Apple macOS Big Sur | <11.0.1 | 11.0.1 |
Apple tvOS | <14.0 | 14.0 |
Apple watchOS | <7.0 | 7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9955 is a vulnerability in ImageIO that allows an out-of-bounds write issue.
CVE-2020-9955 affects Apple tvOS versions up to and excluding 14.0.
CVE-2020-9955 affects Apple iOS versions up to and excluding 14.0.
CVE-2020-9955 affects Apple iPadOS versions up to and excluding 14.0.
CVE-2020-9955 affects Apple macOS Big Sur versions up to and excluding 11.0.1.
CVE-2020-9955 affects Apple watchOS versions up to and excluding 7.0.
To fix CVE-2020-9955, update your Apple device to the latest version of the affected software.
You can find more information about CVE-2020-9955 on the Apple support website.