First published: Thu Nov 05 2020(Updated: )
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to execute arbitrary code with kernel privileges.
Credit: Google Project Zero Google Project Zero Google Project Zero Google Project Zero Google Project Zero Google Project Zero Google Project Zero Google Project Zero product-security@apple.com product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Big Sur | <11.0.1 | 11.0.1 |
Apple macOS Catalina Supplemental Update | <10.15.7 | 10.15.7 |
Apple macOS Catalina Update | <10.15.7 | 10.15.7 |
Apple High Sierra | ||
Apple Mojave | ||
Apple watchOS | <5.3.9 | 5.3.9 |
Apple watchOS | <6.2.9 | 6.2.9 |
Apple watchOS | <7.1 | 7.1 |
Apple iOS | <12.4.9 | 12.4.9 |
Apple Multiple Products | ||
Apple iOS | <14.2 | 14.2 |
Apple iPadOS | <14.2 | 14.2 |
Apple Icloud Windows | <11.5 | |
Apple Itunes Windows | <12.11 | |
Apple iPadOS | <14.2 | |
Apple iPhone OS | <12.4.9 | |
Apple iPhone OS | >=14.0<14.2 | |
Apple Mac OS X | <10.15.7 | |
Apple macOS | >=11.0<11.0.1 | |
Apple watchOS | <5.3.9 | |
Apple watchOS | >=6.0<6.2.9 | |
Apple watchOS | >=7.0<7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2020-27932 is a type confusion vulnerability found in Apple iOS, iPadOS, macOS, and watchOS.
CVE-2020-27932 has the potential to allow a malicious application to execute code with kernel privileges.
Apple iOS, iPadOS, macOS, and watchOS are affected by CVE-2020-27932.
To fix CVE-2020-27932, it is recommended to update your Apple device to the latest available software version.
You can find more information about CVE-2020-27932 on the official Apple support page.