CVE-2019-20044: Apple iPadOS
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with a module that calls setuid().
Affected products
- Apple iPadOS: before 13.5 (fixed in 13.5)
- Apple iPhone OS: before 13.5 (fixed in 13.5)
- Apple Mac OS X: before 10.15.5 (fixed in 10.15.5); from 10.13.0, before 10.13.6 (fixed in 10.13.6); from 10.14.0, before 10.14.6 (fixed in 10.14.6); from 10.15, before 10.15.5 (fixed in 10.15.5); version 10.13.6 only; version 10.14.6 only
- Apple tvOS: before 13.4.5 (fixed in 13.4.5)
- Apple watchOS: before 6.2.5 (fixed in 6.2.5)
- Debian Debian Linux: version 8.0 only; version 9.0 only
- Fedoraproject Fedora: version 30 only; version 31 only
- Zsh Zsh: before 5.8 (fixed in 5.8)
Published 2020-02-24. Last modified 2026-06-17.