Let's Debug Together: CVE-2020-9992
ID: 98cd954a-c8ea-5e46-8f2f-73e44e176f06
STIX ID: report--98cd954a-c8ea-5e46-8f2f-73e44e176f06
Feed Name: Zimperium Blog
Threat Score
**c0ntextomy** is a design flaw in Apple’s MobileDevice.framework and developer tools (Xcode/debugserver) where an SSL context is discarded after handshake, allowing an attacker on the same network to perform a MITM/downgrade attack to hijack Wi‑Fi debug sessions and achieve remote code execution and potential data exfiltration; patches are provided in Xcode 12 and iOS/iPadOS/tvOS 14 but older versions remain partially vulnerable and a PoC exists.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
