Executive brief
A type confusion vulnerability in the Apple XNU kernel (specifically related to turnstiles) allows a malicious application to execute arbitrary code with kernel privileges. The issue was addressed through improved state handling across multiple Apple operating systems.
Affected products
- Apple iOS < 12.4.9, 14.0 to < 14.2
- Apple iPadOS < 14.2
- Apple macOS < 11.0.1, 10.15.7 Supplemental Update
- Apple watchOS < 5.3.9, 6.0 to < 6.2.9, 7.0 to < 7.1
- Apple iCloud for Windows < 11.5
- Apple iTunes for Windows < 12.11
Timeline
- 2020-12-09: disclosed: Initial NVD analysis and disclosure
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2020-11-05: patched: Fixed in iOS 14.2 and iPadOS 14.2