CVE Vulnerabilities

CVE-2020-9885

Insufficient Verification of Data Authenticity

Published: Oct 16, 2020 | Modified: Jan 09, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional verification. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6, tvOS 13.4.8, watchOS 6.2.8. A user that is removed from an iMessage group could rejoin the group.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Ipados Apple * 13.6 (excluding)
Iphone_os Apple * 13.6 (excluding)
Mac_os_x Apple * 10.15.6 (excluding)
Tvos Apple * 13.4.8 (excluding)
Watchos Apple * 6.2.8 (excluding)

References