Vulnerability record · CVE-2020-9818 · published 9 June 2020
CVE-2020-9818: Apple iOS, iPadOS and watchOS Mail out-of-bounds write
Apple · Ipados
An out-of-bounds write in Apple iOS, iPadOS and watchOS was fixed by improved bounds checking in iOS 13.5, iPadOS 13.5, iOS 12.4.7 and watchOS 6.2.5. Processing a maliciously crafted mail message can cause unexpected memory modification or application termination. Because it is a memory-corruption flaw reachable through ordinary mail handling, it carries code-execution risk on unpatched devices.
Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, iOS 12.4.7, watchOS 6.2.5. Processing a maliciously crafted mail message may lead to unexpected memory modification or application termination.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is listed in CISA KEV with confirmed exploitation and high CVSS impact, but requires user interaction and is fixed by widely available vendor updates.
What it is
An out-of-bounds write in Apple iOS, iPadOS and watchOS was fixed by improved bounds checking in iOS 13.5, iPadOS 13.5, iOS 12.4.7 and watchOS 6.2.5. Processing a maliciously crafted mail message can cause unexpected memory modification or application termination. Because it is a memory-corruption flaw reachable through ordinary mail handling, it carries code-execution risk on unpatched devices.
Impact
An attacker who delivers a crafted mail message can corrupt memory in the mail-handling path, potentially achieving code execution in the context of the affected process or at minimum crashing it. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network via a maliciously crafted mail message; the vector shows no privileges required but user interaction required, meaning the target must open or otherwise process the message. No authentication is needed by the attacker.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2021-11-03, indicating real-world exploitation; EPSS 30-day probability is about 2.3 percent (82nd percentile). References are vendor advisories and the CISA KEV entry, with no public exploit write-up tagged.
What to do
- Update to iOS 13.5 or later, iPadOS 13.5 or later, or watchOS 6.2.5 or later; older devices should move to iOS 12.4.7.
- Verify patch state across all managed iPhones, iPads and Apple Watches, including devices that rarely connect to management.
- Restrict or filter inbound mail with untrusted attachments and HTML content at the mail gateway where feasible.
- Treat unpatched, out-of-support Apple devices as untrusted and isolate them from sensitive mail accounts.
Detection
- Monitor for mail client crashes or abnormal terminations on Apple devices, especially repeated crashes tied to specific messages.
- Hunt for unexpected child processes or network connections spawned by Mail or related message-handling processes.
- Review device management and MDM inventories for iOS, iPadOS and watchOS versions below the fixed releases.
- Correlate mail gateway logs for messages with suspicious attachments or markup sent to Apple device users around reported crash times.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-9818 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/HT211168 | Release NotesVendor Advisory |
| https://support.apple.com/HT211169 | Release NotesVendor Advisory |
| https://support.apple.com/HT211175 | Release NotesVendor Advisory |
| https://support.apple.com/HT211168 | Release NotesVendor Advisory |
| https://support.apple.com/HT211169 | Release NotesVendor Advisory |
| https://support.apple.com/HT211175 | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9818 | US Government Resource |
Track CVE-2020-9818 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-9818), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.