First published: Thu Nov 05 2020(Updated: )
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processing a maliciously crafted font may lead to arbitrary code execution.
Credit: Google Project Zero Google Project Zero Google Project Zero Google Project Zero Google Project Zero Google Project Zero product-security@apple.com Google Project Zero Google Project Zero product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple watchOS | <7.1 | 7.1 |
Apple iOS | <14.2 | 14.2 |
Apple iPadOS | <14.2 | 14.2 |
Apple iOS | <12.4.9 | 12.4.9 |
Apple watchOS | <6.2.9 | 6.2.9 |
Apple watchOS | <5.3.9 | 5.3.9 |
Apple macOS Catalina Supplemental Update | <10.15.7 | 10.15.7 |
Apple macOS Catalina Update | <10.15.7 | 10.15.7 |
Apple macOS Big Sur | <11.0.1 | 11.0.1 |
Apple High Sierra | ||
Apple Mojave | ||
Apple iPadOS | <14.2 | |
Apple iPhone OS | <12.4.9 | |
Apple iPhone OS | >=14.0<14.2 | |
Apple Mac OS X | <10.15.7 | |
Apple macOS | >=11.0<11.0.1 | |
Apple watchOS | <5.3.9 | |
Apple watchOS | >=6.0<6.2.9 | |
Apple watchOS | >=7.0<7.1 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-27930 is a memory corruption vulnerability in Apple iOS, iPadOS, macOS, and watchOS FontParser.
Apple iOS, iPadOS, macOS, and watchOS are affected by CVE-2020-27930.
The severity of CVE-2020-27930 is not specified in the provided information.
To fix CVE-2020-27930, update your Apple iOS, iPadOS, macOS, and watchOS to the recommended versions provided by Apple.
You can find more information about CVE-2020-27930 on the official Apple support page.