Junglewise Threat Intelligence

CVE-2020-27932: Apple Multiple Products Type Confusion Vulnerability

CVE-2020-27932 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Apple macOS, Apple iPadOS, Apple watchOS, Apple Multiple Products. Vendors: Apple.

Executive brief

A type confusion vulnerability in the Apple XNU kernel (specifically related to turnstiles) allows a malicious application to execute arbitrary code with kernel privileges. The issue was addressed through improved state handling across multiple Apple operating systems.

Affected products

  • Apple iOS < 12.4.9, 14.0 to < 14.2
  • Apple iPadOS < 14.2
  • Apple macOS < 11.0.1, 10.15.7 Supplemental Update
  • Apple watchOS < 5.3.9, 6.0 to < 6.2.9, 7.0 to < 7.1
  • Apple iCloud for Windows < 11.5
  • Apple iTunes for Windows < 12.11

Timeline

  • 2020-12-09: disclosed: Initial NVD analysis and disclosure
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2020-11-05: patched: Fixed in iOS 14.2 and iPadOS 14.2

Related threats