CVE-2020-9934
Apple Ipados ≤ 13.6
Raw vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NSummary
CVE-2020-9934 is a medium-severity an unspecified weakness vulnerability in Apple Ipados. Its CVSS base score is 5.5 (Medium).
Operationally, ranked in the top 13% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
An issue existed in the handling of environment variables on Apple platforms. The vulnerability affected iOS, iPadOS, and macOS, and was addressed through improved validation of those variables. It is fixed in iOS 13.6, iPadOS 13.6, and macOS Catalina 10.15.6. The flaw carries a CVSS score of 5.5 and permits disclosure of sensitive user information.
A local user with low privileges can exploit the weakness without user interaction. By supplying crafted environment variables, an attacker can read confidential data that should otherwise remain protected from the local account.
Apple security advisories HT211288 and HT211289 describe the patches that resolve the issue in the listed operating system releases. The vulnerability is also tracked in the CISA Known Exploited Vulnerabilities catalog, indicating confirmed real-world exploitation activity.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2020-30713
Vulnerability Data
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.
- CWE(s)
- KEV Date Added
- 08 September 2022
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.