Skip to content
COOEY

EXPOSURES › CVE-2020-9818

CVE-2020-9818

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-9818 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Apple iOS, iPadOS, and watchOS Mail contained an out-of-bounds write vulnerability allowing memory modification or app termination via malicious mail messages.

This out-of-bounds write flaw in the Mail app allowed attackers to modify memory or crash applications by processing specially crafted emails. DIB organizations must ensure all Apple devices are patched promptly, as unpatched versions remain vulnerable to exploitation in the wild. The failure highlights the ongoing risk of relying on mobile devices without rigorous patch management.

Shame score — A known vulnerability in a widely deployed consumer OS that was actively exploited in the wild, indicating a failure to patch before exploitation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apple iOS, iPadOS, and watchOS Mail contains an out-of-bounds write vulnerability which may allow memory modification or application termination when processing a maliciously crafted mail message.

SENTIMENT · TRUSTED SOURCES
synthesis neutral +0.00
No sentiment expressed; sources are CVE databases with no commentary on Apple's handling.
cooey ↗ neutral +0.00
Neutral; CVE database entry with no sentiment.
app.opencve.io ↗ neutral +0.00
Neutral; CVE database entry with no sentiment.
www.cvefind.com ↗ neutral +0.00
Neutral; CVE database entry with no sentiment.
kev.5sn.com ↗ neutral +0.00
Neutral; CVE database entry with no sentiment.
SentinelOne ↗ neutral +0.00
Neutral; CVE database entry with no sentiment.
github.com ↗ neutral +0.00
Neutral; CVE database entry with no sentiment.
cve.akaoma.com ↗ neutral +0.00
Neutral; CVE database entry with no sentiment.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.