SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2020-9934

Apple iOS, iPadOS, and macOS Input Validation Vulnerability

KEVMEDIUM 5.5EPSS 3.21%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 29 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
3.21% probability · 87th percentile
CISA KEV
Listed 8 September 2022 · due 29 September 2022
Affected
apple/ipados · apple/iphone os · apple/mac os x
Source
product-security@apple.com

CISA notes

Apply updates per vendor instructions. https://support.apple.com/en-us/HT211288, https://support.apple.com/en-us/HT211289; https://nvd.nist.gov/vuln/detail/CVE-2020-9934

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.