CVE-2020-9934
Apple iOS, iPadOS, and macOS Input Validation Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 29 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 3.21% probability · 87th percentile
- CISA KEV
- Listed 8 September 2022 · due 29 September 2022
- Affected
- apple/ipados · apple/iphone os · apple/mac os x
- Source
- product-security@apple.com
CISA notes
Apply updates per vendor instructions. https://support.apple.com/en-us/HT211288, https://support.apple.com/en-us/HT211289; https://nvd.nist.gov/vuln/detail/CVE-2020-9934
References
- https://support.apple.com/HT211288Release Notes, Vendor Advisory
- https://support.apple.com/HT211289Release Notes, Vendor Advisory
- https://support.apple.com/HT211288Release Notes, Vendor Advisory
- https://support.apple.com/HT211289Release Notes, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9934US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.