First published: Thu Nov 12 2020(Updated: )
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with kernel privileges.
Credit: ABC Research s.r.o. Trend Micro Zero Day InitiativeXiaolong Bai Min (Spark) Zheng Alibaba Inc Luyi Xing Indiana University Bloomington product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS | <11.0.1 | 11.0.1 |
Apple macOS | <11.1 | 11.1 |
macOS Catalina | ||
macOS Mojave | ||
Apple iOS and macOS | >=10.14<10.14.6 | |
Apple iOS and macOS | >=10.15<10.15.7 | |
Apple iOS and macOS | =10.14.6 | |
Apple iOS and macOS | =10.14.6-security_update_2019-001 | |
Apple iOS and macOS | =10.14.6-security_update_2019-002 | |
Apple iOS and macOS | =10.14.6-security_update_2020-001 | |
Apple iOS and macOS | =10.14.6-security_update_2020-002 | |
Apple iOS and macOS | =10.14.6-security_update_2020-003 | |
Apple iOS and macOS | =10.14.6-security_update_2020-004 | |
Apple iOS and macOS | =10.14.6-security_update_2020-005 | |
Apple iOS and macOS | =10.14.6-security_update_2020-006 | |
Apple iOS and macOS | =10.14.6-supplemental_update | |
Apple iOS and macOS | =10.14.6-supplemental_update_2 | |
Apple iOS and macOS | =10.15.7 | |
Apple iOS and macOS | =10.15.7-supplemental_update | |
macOS | >=11.0<11.1 | |
macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-27897 is an out-of-bounds write vulnerability in the Intel Graphics Driver that has been addressed with improved bounds checking.
The severity of CVE-2020-27897 is not specified in the provided information.
CVE-2020-27897 affects macOS Big Sur versions up to and including 11.0.1, and macOS Catalina and Mojave are also potentially affected.
To mitigate CVE-2020-27897, update your macOS Big Sur to version 11.1 or later when available, as Apple has addressed this vulnerability in macOS Big Sur 11.1.
More information about CVE-2020-27897 can be found on the Apple support page: [https://support.apple.com/en-us/HT212011](https://support.apple.com/en-us/HT212011)