
Cloud Vulnerability DB
A community-led vulnerabilities database
A use after free issue was discovered in Apple's operating systems affecting macOS Big Sur, watchOS, iOS, iPadOS, macOS Catalina, and other versions. The vulnerability (CVE-2020-9949) was reported by security researcher Proteas and fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra, and tvOS 14.0 (Apple Support).
The vulnerability is a use-after-free memory corruption issue in the CoreCapture component that was addressed with improved memory management. The vulnerability has been assigned a CVSS v3.1 Base Score of 7.8 (HIGH) with vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (NVD).
If exploited, this vulnerability could allow a malicious application to execute arbitrary code with kernel privileges, potentially giving the attacker full control over the affected device (Apple Support).
The vulnerability requires local access and user interaction to exploit. While the vulnerability is serious, there were no reports of this vulnerability being exploited in the wild at the time of disclosure (NVD).
Apple addressed this vulnerability by releasing security updates across multiple operating systems. Users should update to macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra, or tvOS 14.0 depending on their device (Apple Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."