Executive brief
A memory corruption vulnerability in the FontParser component of multiple Apple operating systems allows for arbitrary code execution. The issue stems from insufficient input validation when processing maliciously crafted fonts.
Affected products
- Apple iOS < 12.4.9, 14.0 to < 14.2
- Apple iPadOS < 14.2
- Apple macOS < 11.0.1, 10.15.7 Supplemental Update, 10.15.7 Update
- Apple watchOS < 5.3.9, 6.0 to < 6.2.9, 7.0 to < 7.1
Timeline
- 2020-12-09: disclosed: Initial NVD analysis and disclosure
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2020-11-05: patched: Addressed in various OS updates including iOS 14.2 and macOS Big Sur 11.0.1
- 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV catalog entry