Vulnerability record · CVE-2020-9934 · published 16 October 2020
CVE-2020-9934: Apple iOS, iPadOS, and macOS environment variable validation flaw exposes user data
Apple · Ipados
An issue in how Apple iOS, iPadOS, and macOS handled environment variables was fixed by improved validation in iOS 13.6, iPadOS 13.6, and macOS Catalina 10.15.6. A local user could view sensitive user information. The record does not specify which environment variables or data were exposed.
Description
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw is in CISA KEV with known exploitation, though it requires local access and has only medium CVSS severity.
What it is
An issue in how Apple iOS, iPadOS, and macOS handled environment variables was fixed by improved validation in iOS 13.6, iPadOS 13.6, and macOS Catalina 10.15.6. A local user could view sensitive user information. The record does not specify which environment variables or data were exposed.
Impact
A local attacker can read sensitive user information that should otherwise be protected. The CVSS vector shows high confidentiality impact with no integrity or availability impact.
Attack surface
The vulnerability is local (AV:L) and requires low privileges (PR:L) with no user interaction (UI:N). It is reached by a local user or process on the affected device, not over the network.
Exploitation
CVE-2020-9934 is listed in CISA KEV, indicating known exploitation in the wild, but the record does not describe the exploit or its availability. EPSS gives a 30-day probability of 0.03208 (87.5th percentile), and no ransomware use is documented.
What to do
- Update to iOS 13.6, iPadOS 13.6, or macOS Catalina 10.15.6 or later as specified in Apple advisories HT211288 and HT211289.
- Apply the vendor updates per CISA KEV required action.
- Restrict local access to trusted users and monitor for unexpected local processes.
- Review environment variable handling in any custom software that runs on affected Apple platforms.
Detection
- Monitor for local processes attempting to read environment variables or sensitive user data outside expected applications.
- Audit endpoint logs for unusual local user activity on unpatched iOS, iPadOS, or macOS systems.
- Track patch status against Apple security updates HT211288 and HT211289.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-9934 to the Known Exploited Vulnerabilities catalog on 8 September 2022 as "Apple iOS, iPadOS, and macOS Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 29 September 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://support.apple.com/HT211288 | Release NotesVendor Advisory |
| https://support.apple.com/HT211289 | Release NotesVendor Advisory |
| https://support.apple.com/HT211288 | Release NotesVendor Advisory |
| https://support.apple.com/HT211289 | Release NotesVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-9934 | US Government Resource |
Track CVE-2020-9934 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-9934), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.