Junglewise Threat Intelligence

CVE-2020-27930: Apple Multiple Products Memory Corruption Vulnerability

CVE-2020-27930 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Apple macOS, Apple iPadOS, Apple watchOS, Apple Multiple Products. Vendors: Apple.

Executive brief

A memory corruption vulnerability in the FontParser component of multiple Apple operating systems allows for arbitrary code execution. The issue stems from insufficient input validation when processing maliciously crafted fonts.

Affected products

  • Apple iOS < 12.4.9, 14.0 to < 14.2
  • Apple iPadOS < 14.2
  • Apple macOS < 11.0.1, 10.15.7 Supplemental Update, 10.15.7 Update
  • Apple watchOS < 5.3.9, 6.0 to < 6.2.9, 7.0 to < 7.1

Timeline

  • 2020-12-09: disclosed: Initial NVD analysis and disclosure
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2020-11-05: patched: Addressed in various OS updates including iOS 14.2 and macOS Big Sur 11.0.1
  • 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV catalog entry

Related threats