CVE-2020-9838: Apple iPadOS

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5. A remote attacker may be able to cause arbitrary code execution.

Affected products

  • Apple iPadOS: before 13.5 (fixed in 13.5)
  • Apple iPhone OS: before 13.5 (fixed in 13.5)

Published 2020-06-09. Last modified 2026-06-17.