
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-9910 is a security vulnerability discovered in multiple Apple products including iOS 13.6, iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, and iCloud for Windows 7.20. The vulnerability was discovered by Samuel Groß of Google Project Zero and was fixed in July 2020. The issue involves a malicious attacker with arbitrary read and write capability being able to bypass Pointer Authentication (Apple Support).
The vulnerability is classified with a CVSS v3.1 Base Score of 8.8 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Multiple issues related to pointer authentication were identified and addressed with improved logic in the WebKit component of affected Apple products (NVD).
If exploited, this vulnerability could allow a malicious attacker with arbitrary read and write capability to bypass Pointer Authentication, potentially leading to unauthorized access and compromise of system security (Apple Support, NVD).
The vulnerability requires the attacker to have arbitrary read and write capabilities to exploit the weakness in pointer authentication. The attack vector is network-based with low attack complexity and requires low privileges, but no user interaction (NVD).
Apple addressed this vulnerability by implementing improved logic in the affected systems. Users should update to iOS 13.6, iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows 11.3, or iCloud for Windows 7.20 depending on their device (Apple Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."