Multiple Vulnerabilities in Apple iOS and iPadOS
Original Issue Date: January 30, 2020
Severity Rating: High
- Apple iOS and iPadOS versions prior to 13.3.1
Multiple vulnerabilities have been reported in Apple iOS and iPadOS which could allow a remote attacker to execute arbitrary code, access sensitive or privileged information, gain elevated privileges, cause memory corruption, cause denial of service conditions or perform cross site scripting attacks on a targeted system.
These vulnerabilities exist due to multiple memory corruption issues, out-of-bounds read error, improper input sanitization, improper memory initialization and access, race condition, buffer overflow, type confusion, improper UI handling and other logical errors in Audio, FaceTime, ImageIO, IOAcceleratorFamily, IPSec, Kernel, libxml2, libxpc, Mail, Messages, Phone, Safari Login AutoFill, Screenshots, WebKit and wifivelocityd components of iOS and iPadOS.
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code, access sensitive or privileged information, gain elevated privileges, cause memory corruption, cause denial of service conditions or perform cross site scripting attacks on a targeted system.
Upgrade Apple iOSand iPadOSas mentioned in the
Apple security updates.
The information provided herein is on "as is" basis, without warranty of any kind.
Email: firstname.lastname@example.org Phone: +91-11-24368572
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
6, CGO Complex, Lodhi Road,
New Delhi - 110 003