VulnerabilityModified
CVE-2020-9989
The issue was addressed with improved deletion.
MEDIUM 5.5EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
The issue was addressed with improved deletion. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A local user may be able to discover a user’s deleted messages.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Affected
- apple/ipados · apple/iphone os · apple/mac os x · apple/watchos
- Source
- product-security@apple.com
References
- http://seclists.org/fulldisclosure/2020/Dec/32Mailing List, Third Party Advisory
- https://support.apple.com/en-us/HT211844Vendor Advisory
- https://support.apple.com/en-us/HT211850Vendor Advisory
- https://support.apple.com/en-us/HT211931Vendor Advisory
- http://seclists.org/fulldisclosure/2020/Dec/32Mailing List, Third Party Advisory
- https://support.apple.com/en-us/HT211844Vendor Advisory
- https://support.apple.com/en-us/HT211850Vendor Advisory
- https://support.apple.com/en-us/HT211931Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.