CVE-2020-9992 is an out-of-bounds read vulnerability affecting multiple Apple products, including iOS, iPadOS, watchOS, tvOS, iCloud for Windows, and iTunes for Windows. The vulnerability can be triggered by processing a maliciously crafted TIFF file, potentially leading to denial-of-service or memory disclosure. The root cause is insufficient input validation when handling TIFF files, allowing an attacker to read memory outside the intended buffer.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a sophisticated proof-of-concept exploit for CVE-2020-9992, a design flaw in Apple's MobileDevice.framework and related development tools that allows an attacker on the same network to hijack remote debugging sessions and gain code execution on iOS, iPadOS, or tvOS devices being debugged over WiFi. The exploit leverages ARP spoofing and a custom Bettercap module (written in Go) to intercept and proxy TCP connections, detect gdb-remote debug sessions, and inject a second, attacker-controlled lldb client into the session. The exploit chain includes: - Network MITM via ARP spoofing and dynamic firewall rules (Bettercap + custom Go module) - Detection and hijacking of gdb-remote debug sessions - Injection of shellcode and post-exploitation modules (written in C and Python) into the target device via the hijacked debug session - Exfiltration of sensitive data (app bundles, audio recordings, contacts, photos) using custom modules The repository is well-structured, with clear separation between the network attack logic (Go), the payload and modules (C/Python), and orchestration scripts. It includes both the exploit logic and post-exploitation tooling for data theft. The exploit is operational and demonstrates real-world impact, but requires attacker access to the same local network as the victim and specific target configurations (remote debugging over WiFi, affected Apple OS versions).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.