First published: Thu Nov 12 2020(Updated: )
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with kernel privileges.
Credit: product-security@apple.com ABC Research s.r.o. Trend Micro Zero Day InitiativeXiaolong Bai Min (Spark) Zheng Alibaba IncLuyi Xing Indiana University BloomingtonABC Research s.r.o. Trend Micro Zero Day InitiativeXiaolong Bai Min (Spark) Zheng Alibaba Inc Luyi Xing Indiana University Bloomington
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Big Sur | <11.1 | 11.1 |
Apple Catalina | ||
Apple Mojave | ||
Apple macOS Big Sur | <11.0.1 | 11.0.1 |
Apple Mac OS X | >=10.14<10.14.6 | |
Apple Mac OS X | >=10.15<10.15.7 | |
Apple Mac OS X | =10.14.6 | |
Apple Mac OS X | =10.14.6-security_update_2019-001 | |
Apple Mac OS X | =10.14.6-security_update_2019-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-001 | |
Apple Mac OS X | =10.14.6-security_update_2020-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-003 | |
Apple Mac OS X | =10.14.6-security_update_2020-004 | |
Apple Mac OS X | =10.14.6-security_update_2020-005 | |
Apple Mac OS X | =10.14.6-security_update_2020-006 | |
Apple Mac OS X | =10.14.6-supplemental_update | |
Apple Mac OS X | =10.14.6-supplemental_update_2 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-10015 is a vulnerability in the Intel Graphics Driver where an out-of-bounds write issue could allow an attacker to execute arbitrary code or cause a denial of service.
macOS Big Sur versions up to and including 11.0.1 and 11.1 are affected, as well as Apple Catalina and Mojave.
The severity of CVE-2020-10015 is not specified, but it is a critical vulnerability that could lead to code execution or denial of service.
Update to macOS Big Sur 11.0.1 or 11.1, or follow the recommendations provided by Apple for Catalina and Mojave.
You can find more information about CVE-2020-10015 on the Apple support website.