First published: Thu Nov 12 2020(Updated: )
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with kernel privileges.
Credit: product-security@apple.com ABC Research s.r.o. Trend Micro Zero Day InitiativeXiaolong Bai Min (Spark) Zheng Alibaba IncLuyi Xing Indiana University BloomingtonABC Research s.r.o. Trend Micro Zero Day InitiativeXiaolong Bai Min (Spark) Zheng Alibaba Inc Luyi Xing Indiana University Bloomington
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | >=10.14<10.14.6 | |
Apple Mac OS X | >=10.15<10.15.7 | |
Apple Mac OS X | =10.14.6 | |
Apple Mac OS X | =10.14.6-security_update_2019-001 | |
Apple Mac OS X | =10.14.6-security_update_2019-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-001 | |
Apple Mac OS X | =10.14.6-security_update_2020-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-003 | |
Apple Mac OS X | =10.14.6-security_update_2020-004 | |
Apple Mac OS X | =10.14.6-security_update_2020-005 | |
Apple Mac OS X | =10.14.6-security_update_2020-006 | |
Apple Mac OS X | =10.14.6-supplemental_update | |
Apple Mac OS X | =10.14.6-supplemental_update_2 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.1 | |
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-27897 is an out-of-bounds write vulnerability in the Intel Graphics Driver that has been addressed with improved bounds checking.
The severity of CVE-2020-27897 is not specified in the provided information.
CVE-2020-27897 affects macOS Big Sur versions up to and including 11.0.1, and macOS Catalina and Mojave are also potentially affected.
To mitigate CVE-2020-27897, update your macOS Big Sur to version 11.1 or later when available, as Apple has addressed this vulnerability in macOS Big Sur 11.1.
More information about CVE-2020-27897 can be found on the Apple support page: [https://support.apple.com/en-us/HT212011](https://support.apple.com/en-us/HT212011)