Vulnerability record · CVE-2020-9907 · published 16 October 2020
CVE-2020-9907: Apple iOS, iPadOS and tvOS out-of-bounds write in kernel code
Apple · Ipados
A memory corruption flaw (out-of-bounds write) in Apple iOS, iPadOS and tvOS was fixed by removing the vulnerable code in iOS 13.6, iPadOS 13.6 and tvOS 13.4.8. Successful abuse lets an application execute arbitrary code with kernel privileges, so it breaks the boundary between user apps and the kernel. The record does not name the specific component or function involved.
Description
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8. An application may be able to execute arbitrary code with kernel privileges.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw gives kernel-level code execution and is confirmed exploited in CISA KEV, though it requires local user interaction to run a malicious app.
What it is
A memory corruption flaw (out-of-bounds write) in Apple iOS, iPadOS and tvOS was fixed by removing the vulnerable code in iOS 13.6, iPadOS 13.6 and tvOS 13.4.8. Successful abuse lets an application execute arbitrary code with kernel privileges, so it breaks the boundary between user apps and the kernel. The record does not name the specific component or function involved.
Impact
An attacker who gets a malicious application running on the device can execute arbitrary code at kernel level, gaining full control of the operating system and bypassing app sandbox restrictions.
Attack surface
The CVSS vector is local (AV:L) with no privileges required (PR:N) but user interaction required (UI:R), meaning the victim must run or open the crafted application. No network or remote vector is described.
Exploitation
CVE-2020-9907 is listed in CISA KEV with a 2022-06-27 addition date, confirming exploitation in the wild; EPSS 30-day probability is about 3.9 percent (89.7th percentile). References are vendor advisories and the KEV entry only, with no public exploit details in this record.
What to do
- Update to iOS 13.6, iPadOS 13.6 or tvOS 13.4.8 or later as directed by Apple advisories HT211288 and HT211290.
- Enforce a minimum OS version baseline on managed iPhones, iPads and Apple TVs and block or flag devices below it.
- Restrict app installation to trusted sources and review enterprise-signed or sideloaded apps, since exploitation requires running a malicious application.
- Treat jailbroken or unmanaged devices as high risk and isolate them from sensitive corporate data and services.
- Monitor Apple security advisories for follow-up fixes affecting the same code path.
Detection
- Inventory iOS, iPadOS and tvOS versions and alert on any device below 13.6 / 13.4.8.
- Hunt for unexpected kernel panics, crashes or reboots on Apple devices that could indicate memory corruption exploitation.
- Review mobile device management logs for sideloaded, enterprise-signed or otherwise untrusted applications on managed devices.
- Correlate endpoint or MDM telemetry for suspicious app behavior immediately preceding kernel-level anomalies.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-9907 to the Known Exploited Vulnerabilities catalog on 27 June 2022 as "Apple Multiple Products Memory Corruption Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 18 July 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/HT211288 | Release NotesVendor Advisory |
| https://support.apple.com/HT211290 | Release NotesVendor Advisory |
| https://support.apple.com/HT211288 | Release NotesVendor Advisory |
| https://support.apple.com/HT211290 | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9907 | US Government Resource |
Track CVE-2020-9907 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-9907), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.