CVE Database · CVE-2020-9907
CVSS v3.1
7.8
EPSS
3.74%
Published
Oct 16, 2020
Modified
Oct 23, 2025
CISA Known Exploited Vulnerability
Added: 2022-06-27 · Due: 2022-07-18
Apply updates per vendor instructions.
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HWeaknesses (CWE)
Affected Products (3)
References (5)