Junglewise Threat Intelligence

CVE-2020-27950: Apple Multiple Products Memory Initialization Vulnerability

CVE-2020-27950 · Severity: critical · CVSS 5.5 · Exploited in the wild · Published 2021-11-03

Technologies: Apple iPadOS, Apple watchOS, Apple macOS, Apple Multiple Products. Vendors: Apple.

Executive brief

Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability in the kernel. A malicious application can exploit this flaw to disclose sensitive kernel memory.

Affected products

  • Apple iOS < 12.4.9, 14.0 - 14.2
  • Apple iPadOS < 14.2
  • Apple macOS < 10.15.7, 11.0 - 11.0.1
  • Apple watchOS < 5.3.9, 6.0 - 6.2.9, 7.0 - 7.1

Timeline

  • 2020-12-09: disclosed: Initial analysis by NIST
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • exploited: Reported as exploited in the wild in the advisory metadata.

Related threats