First published: Wed Sep 16 2020(Updated: )
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A malicious application may be able to elevate privileges.
Credit: Zhiwei Yuan Trend Micro iCore TeamJunzhi Lu Mickey Jin Trend Micro product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <11.0.1 | 11.0.1 |
Apple iOS and iPadOS | <14.0 | 14.0 |
Apple iOS, iPadOS, and macOS | <14.0 | 14.0 |
Apple iOS, iPadOS, and macOS | <14.0 | |
iPhone OS | <14.0 | |
Apple iOS and macOS | <11.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9996 is a vulnerability in NetworkExtension that allows for a use after free issue, which has been addressed with improved memory management.
CVE-2020-9996 affects Apple iOS up to version 14.0, Apple iPadOS up to version 14.0, and Apple macOS Big Sur up to version 11.0.1.
The severity of CVE-2020-9996 is not specified.
To fix CVE-2020-9996, ensure you have installed the latest security updates and patches provided by Apple for the affected software versions.
You can find more information about CVE-2020-9996 on the official Apple support website: https://support.apple.com/en-us/HT211850