EXPOSURES › CVE-2020-9818
CVE-2020-9818
HIGH ⌖ ON CISA KEV · EXPLOITEDApple iOS, iPadOS, and watchOS Mail contained an out-of-bounds write vulnerability allowing memory modification or app termination via malicious mail messages.
This out-of-bounds write flaw in the Mail app allowed attackers to modify memory or crash applications by processing specially crafted emails. DIB organizations must ensure all Apple devices are patched promptly, as unpatched versions remain vulnerable to exploitation in the wild. The failure highlights the ongoing risk of relying on mobile devices without rigorous patch management.
Shame score — A known vulnerability in a widely deployed consumer OS that was actively exploited in the wild, indicating a failure to patch before exploitation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.