Cyber Resilience

CVE-2020-9934

Apple Ipados ≤ 13.6

CISA KEVActive ExploitationEUVD Exploited
Published
16 October 2020
Modified
23 October 2025
KEV Added
08 September 2022
Patch / advisory
CVSS Score v3.1 5.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.032 87th percentile
Risk Priority 75 floored blend · peak EPSS

Summary

CVE-2020-9934 is a medium-severity an unspecified weakness vulnerability in Apple Ipados. Its CVSS base score is 5.5 (Medium).

Operationally, ranked in the top 13% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

An issue existed in the handling of environment variables on Apple platforms. The vulnerability affected iOS, iPadOS, and macOS, and was addressed through improved validation of those variables. It is fixed in iOS 13.6, iPadOS 13.6, and macOS Catalina 10.15.6. The flaw carries a CVSS score of 5.5 and permits disclosure of sensitive user information.

A local user with low privileges can exploit the weakness without user interaction. By supplying crafted environment variables, an attacker can read confidential data that should otherwise remain protected from the local account.

Apple security advisories HT211288 and HT211289 describe the patches that resolve the issue in the listed operating system releases. The vulnerability is also tracked in the CISA Known Exploited Vulnerabilities catalog, indicating confirmed real-world exploitation activity.

EU & UK References

Vulnerability Data

An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.

CWE(s)
KEV Date Added
08 September 2022

Related Threats

CVEs Like This One

CVE-2021-30869Same product: Apple Ipadosboth on KEV
CVE-2023-42824Same product: Apple Ipadosboth on KEV
CVE-2021-30983Same product: Apple Ipadosboth on KEV
CVE-2019-7286Same product: Apple Iphone Osboth on KEV
CVE-2019-6223Same product: Apple Iphone Osboth on KEV
CVE-2023-41974Same product: Apple Ipadosboth on KEV
CVE-2025-24200Same product: Apple Ipadosboth on KEV
CVE-2022-42827Same product: Apple Ipadosboth on KEV
CVE-2020-27930Same product: Apple Ipadosboth on KEV
CVE-2020-9859Same product: Apple Ipadosboth on KEV

Affected Assets

apple
ipados
≤ 13.6
apple
iphone os
≤ 13.6
apple
mac os x
≤ 10.15.6

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References