LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-9934: Apple iOS, iPadOS, and macOS Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 8, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 29, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-9934 to its Known Exploited Vulnerabilities catalog on Sep 8, 2022, with a federal patch deadline of Sep 29, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple iOS, iPadOS, and macOS contain an unspecified vulnerability involving input validation which can allow a local attacker to view sensitive user information.

CVE-2020-9934 is an input validation vulnerability in Apple iOS, iPadOS, and macOS. A local attacker who can run code or interact with the device may be able to view sensitive user information that should otherwise remain protected.

It matters because local access is common on shared, lost, stolen, or lightly managed endpoints. Successful abuse can expose personal or organizational data without needing remote network access. Confirm exact scope and fixed builds against Apple’s advisory.

How it works

The flaw is described as an input validation weakness. In this class of issue, software does not adequately check or sanitize data it receives before using it in a sensitive context. That can allow a local attacker to influence processing in a way that reveals information the OS or apps intended to keep private.

Public detail on the precise component and abuse path is limited. Treat it as a local information-disclosure issue: an attacker already able to execute or interact on the device supplies crafted input that bypasses intended checks and surfaces sensitive user data. Do not assume remote wormability or privilege escalation beyond what the vendor advisory states; verify mechanics there.

Am I affected? How to find it in your systems

This affects Apple iOS, iPadOS, and macOS devices. These typically appear as employee iPhones and iPads, corporate Macs, BYOD endpoints enrolled in MDM, and lab or kiosk systems.

How to remediate

Patch first. Apply the updates Apple released for this vulnerability on iOS, iPadOS, and macOS exactly as directed in the vendor advisory and CISA’s required action: follow vendor instructions.

If you can't patch immediately

Reduce exposure until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches and exposure of user or organizational information. If you suspect local compromise or sensitive data access on affected devices, follow your incident-response process: isolate the device, preserve logs, rotate credentials that may have been present, and assess what data was reachable. You can also run a free exposure scan of your email addresses against known breach datasets to see whether associated credentials or personal data have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · iOS, iPadOS, and macOS
Added to CISA KEVSep 8, 2022
Federal patch deadlineSep 29, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities