Security features bypass in watchOS - CVE-2020-9974

 

Security features bypass in watchOS - CVE-2020-9974

Published: November 6, 2020


Vulnerability identifier: #VU48185
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9974
CWE-ID: CWE-254
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists within the OS kernel that allows a local user to run a specially crafted program and determine kernel memory layout. This vulnerability can be used to bypass implemented security restrictions and leverage exploitation of other vulnerabilities.


Affected software

watchOS
macOS
tvOS
iPadOS
Apple iOS

How to mitigate CVE-2020-9974

Install updates from vendor's website.

watchOS - update to 7.1 18R590
tvOS - update to 14.2 18K57
iPadOS - update to 14.2 18B92
Apple iOS - update to 14.2 18B92

External References

Related Security Bulletins