CVE-2020-36331: Apple iPadOS

Critical severity, CVSS 9.1. EPSS: 2.3% chance of exploitation in the next 30 days.

A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.

Affected products

  • Apple iPadOS: before 14.7 (fixed in 14.7)
  • Apple iPhone OS: before 14.7 (fixed in 14.7)
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified
  • Red Hat Enterprise Linux: version 8.0 only
  • Webmproject Libwebp: before 1.0.1 (fixed in 1.0.1)

Published 2021-05-21. Last modified 2026-06-17.