First published: Thu Nov 05 2020(Updated: )
An out-of-bounds write was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Big Sur 11.0.1. Processing a maliciously crafted PDF may lead to arbitrary code execution.
Credit: S.Y. ZecOps Mobile XDRan anonymous researcher S.Y. ZecOps Mobile XDRan anonymous researcher product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS | <14.2 | 14.2 |
Apple iPadOS | <14.2 | 14.2 |
Apple macOS Big Sur | <11.0.1 | 11.0.1 |
Apple iPadOS | <14.2 | |
Apple iPhone OS | <14.2 | |
Apple macOS | <11.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-9897 is a vulnerability in CoreGraphics that allows for an out-of-bounds write, which has been addressed with improved input validation.
CVE-2020-9897 affects Apple iOS up to version 14.1, Apple iPadOS up to version 14.1, and Apple macOS Big Sur up to version 11.0.1.
CVE-2020-9897 is a vulnerability with a severity rating of moderate.
To fix CVE-2020-9897, update your Apple devices to the latest versions: Apple iOS 14.2, Apple iPadOS 14.2, or Apple macOS Big Sur 11.0.1.
You can find more information about CVE-2020-9897 on the Apple support website: [support.apple.com/en-us/HT211929](support.apple.com/en-us/HT211929) and [support.apple.com/en-us/HT211931](support.apple.com/en-us/HT211931).