SB2020022727 - Buffer overflow in Apple watchOS



SB2020022727 - Buffer overflow in Apple watchOS

Published: February 27, 2020 Updated: July 17, 2020

Security Bulletin ID SB2020022727
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Buffer overflow (CVE-ID: CVE-2020-3834)

The vulnerability allows a local non-authenticated attacker to execute arbitrary code.

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.


Remediation

Install update from vendor's website.