Back to Labs
Security Advisory

CVE-2020-9909

About

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.

Weakness (CWE):CWE-125

Rainforest analyst review

This Apple kernel out-of-bounds read helps bypass kernel memory mitigations, but the advisory states the essential precondition outright: the attacker must have already achieved kernel code execution. It's not a way onto the device, it's a way to make an existing deep compromise more effective.

That places it firmly as a link in an exploit chain rather than a standalone threat. The actors who care about a mitigation-bypass primitive at this level are the ones building sophisticated iOS implants or jailbreaks, not opportunistic attackers, and it only has value once earlier stages have already succeeded.

We rank it down as an isolated finding while recognizing its role in chaining, and we handle it through mobile fleet patch hygiene across the affected iOS, iPadOS, tvOS, and watchOS versions. Keeping devices current is what denies chain-builders the pieces they need, so patch level is the metric that matters.

References

Related CVEs

Frequently asked questions

What is CVE-2020-9909?

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8. An attacker that has already achieved kernel code execution may be able to bypass kernel memory mitigations.

How severe is CVE-2020-9909?

CVE-2020-9909 carries a CVSS 3.1 base score of 5.9, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 66 out of 100, in the elevated band.

How is CVE-2020-9909 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N): attack vector Network, attack complexity High, privileges required None, user interaction None. Impact on confidentiality High, integrity None and availability None.

Which products are affected by CVE-2020-9909?

Public advisories list the following as affected: ipados, iphone os, tvos, watchos. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2020-9909?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email