First published: Mon Dec 14 2020(Updated: )
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted audio file may disclose restricted memory.
Credit: Anonymous Trend Micro Zero Day InitiativeAnonymous Trend Micro Zero Day InitiativeAnonymous Trend Micro Zero Day InitiativeAnonymous Trend Micro Zero Day Initiative product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple watchOS | <7.2 | 7.2 |
Apple tvOS | <14.3 | 14.3 |
Apple iOS | <14.3 | 14.3 |
Apple iPadOS | <14.3 | 14.3 |
Apple macOS Big Sur | <11.1 | 11.1 |
Apple Catalina | ||
Apple Mojave | ||
Apple iPadOS | <14.3 | |
Apple iPhone OS | <14.3 | |
Apple Mac OS X | >=10.14<10.14.6 | |
Apple Mac OS X | >=10.15<10.15.7 | |
Apple Mac OS X | =10.14.6 | |
Apple Mac OS X | =10.14.6-security_update_2019-001 | |
Apple Mac OS X | =10.14.6-security_update_2019-002 | |
Apple Mac OS X | =10.14.6-security_update_2019-006 | |
Apple Mac OS X | =10.14.6-security_update_2019-007 | |
Apple Mac OS X | =10.14.6-security_update_2020-001 | |
Apple Mac OS X | =10.14.6-security_update_2020-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-003 | |
Apple Mac OS X | =10.14.6-security_update_2020-004 | |
Apple Mac OS X | =10.14.6-security_update_2020-005 | |
Apple Mac OS X | =10.14.6-security_update_2020-006 | |
Apple Mac OS X | =10.14.6-supplemental_update | |
Apple Mac OS X | =10.14.6-supplemental_update_2 | |
Apple Mac OS X | =10.15.7 | |
Apple Mac OS X | =10.15.7-supplemental_update | |
Apple macOS | >=11.0<11.1.0 | |
Apple tvOS | <14.3 | |
Apple watchOS | <7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-29610 is a vulnerability in the Audio component that allows an out-of-bounds read due to improved input validation.
CVE-2020-29610 affects Apple iOS up to version 14.3, Apple iPadOS up to version 14.3, Apple tvOS up to version 14.3, Apple macOS Big Sur up to version 11.1, Apple Catalina, Apple Mojave, and Apple watchOS up to version 7.2.
The severity of CVE-2020-29610 is not specified in the information provided.
To fix CVE-2020-29610, update your Apple device to the recommended versions: Apple iOS 14.3, Apple iPadOS 14.3, Apple tvOS 14.3, Apple macOS Big Sur 11.1, or Apple watchOS 7.2.
You can find more information about CVE-2020-29610 on the Apple support website. Visit the following links: [link1](https://support.apple.com/en-us/HT212009), [link2](https://support.apple.com/en-us/HT212005), [link3](https://support.apple.com/en-us/HT212003).