LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-9859: Apple Multiple Products Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-9859 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple iOS, iPadOS, macOS, watchOS, and tvOS contain an unspecified vulnerability that may allow an application to execute code with kernel privileges.

CVE-2020-9859 is a code-execution vulnerability affecting multiple Apple operating systems—iOS, iPadOS, macOS, watchOS, and tvOS. An application running on a vulnerable device may be able to execute code with kernel privileges, which can undermine the isolation that normally protects the rest of the system.

For IT and security teams this matters because kernel-level code execution can lead to full device compromise, persistence, and further lateral movement or data access. Public detail on exact mechanics is limited; confirm all version and configuration specifics against the vendor advisory.

How it works

The weakness is classified as CWE-415 (Double Free). In this class of flaw, memory that has already been freed is freed again, which can corrupt allocator metadata and allow an attacker to influence subsequent allocations.

According to the CISA summary, the vulnerability is unspecified beyond the outcome: an application may execute code with kernel privileges. In practical terms, a malicious or compromised app on an affected Apple device could trigger the double-free condition and escalate from user context into the kernel. Exact trigger conditions, affected components, and exploit requirements are not detailed in the provided facts and must be confirmed against Apple’s advisory.

Am I affected? How to find it in your systems

The vulnerability affects Apple’s mobile, desktop, wearable, and TV platforms: iOS, iPadOS, macOS, watchOS, and tvOS. These typically appear as employee iPhones and iPads, Mac endpoints (including those managed via MDM), Apple Watches, and Apple TV devices on corporate or BYOD networks.

How to remediate

Patch first. Apply the updates Apple released for the affected OS families exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and subsequent data exposure. Known ransomware use of this CVE is not documented in the provided facts. If you suspect compromise, follow your incident-response process: isolate the device, preserve logs, and rotate credentials that may have been accessible from it. You can also run a free exposure scan of your email addresses against known breach data to check whether associated accounts appear in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
WeaknessCWE-415
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities