Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

Pointer Authentication Code bypass in Apple operating systems

IdentifiersCVE-2020-9870CWE-693

CVE-2020-9870 is an Apple mitigation-bypass vulnerability described by Apple as a logic issue fixed through improved validation in iOS 13.6, iPadOS 13.6, macOS Catalina 10.15.6, and tvOS 13.4.8. According to the provided content, the issue allows an attacker who already has memory write capability to bypass pointer authentication codes (PAC/PACCage-related protections) and execute arbitrary code. The supporting context places this bug in a WebKit/JavaScriptCore exploit chain as one of the mitigation bypasses used alongside CVE-2020-9802, indicating it weakens a platform hardening mechanism rather than serving as the initial memory-corruption primitive itself. Specific vulnerable functions or code paths are not provided in the supplied material.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can defeat Apple pointer-authentication-based exploit mitigations, allowing an attacker with an existing memory write primitive to convert that capability into arbitrary code execution. In practical exploit chains, this materially increases exploit reliability and enables post-corruption execution on affected Apple platforms, including Safari/WebKit-driven chains discussed in the supplied context.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure to likely exploit delivery vectors such as untrusted web content in Safari/WebKit and limit attacker opportunities to obtain an initial memory write primitive. Standard compensating controls may reduce risk, but no complete mitigation is provided in the supplied content short of installing Apple's fixes.

Remediation

Patch, then assume compromise.

Apply the vendor fixes: iOS 13.6, iPadOS 13.6, macOS Catalina 10.15.6, or tvOS 13.4.8, or later supported releases incorporating Apple's validation improvements. Because the issue is a mitigation bypass used in exploit chains, remediation should include patching both this CVE and any associated initial-access or memory-corruption vulnerabilities used with it.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
AppleIpadosoperating_system
AppleIphone Osoperating_system
AppleMac Os Xoperating_system
AppleTvosoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware1

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity

Community discussion across Reddit, Mastodon, and other social sources.