CVE-2019-20044: Apple iPadOS

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with a module that calls setuid().

Affected products

  • Apple iPadOS: before 13.5 (fixed in 13.5)
  • Apple iPhone OS: before 13.5 (fixed in 13.5)
  • Apple Mac OS X: before 10.15.5 (fixed in 10.15.5); from 10.13.0, before 10.13.6 (fixed in 10.13.6); from 10.14.0, before 10.14.6 (fixed in 10.14.6); from 10.15, before 10.15.5 (fixed in 10.15.5); version 10.13.6 only; version 10.14.6 only
  • Apple tvOS: before 13.4.5 (fixed in 13.4.5)
  • Apple watchOS: before 6.2.5 (fixed in 6.2.5)
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 30 only; version 31 only
  • Zsh Zsh: before 5.8 (fixed in 5.8)

Published 2020-02-24. Last modified 2026-06-17.