An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Catalina 10.15.6. A local user may be able to view sensitive user information.
Kernel. Multiple memory corruption issues were addressed with improved state management.
Call History. This issue was addressed with a new entitlement.
An issue existed in the handling of tabs displaying picture in picture video. The issue was corrected with improved state handling. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user's private browsing activity may be unexpectedly saved in Screen Time.
Vim. Multiple issues were addressed by updating to version 8.1.1850.
Bluetooth. An out-of-bounds read was addressed with improved input validation.
CoreFoundation. A permissions issue existed. This issue was addressed with improved permission validation.
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A malicious application may be able to execute arbitrary code with kernel privileges.
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. An application may be able to read restricted memory.
Apple HSSPI Support. A memory corruption issue was addressed with improved memory handling.
AppleGraphicsControl. Multiple memory corruption issues were addressed with improved state management.
Bluetooth. An out-of-bounds read was addressed with improved input validation.
Bluetooth. An out-of-bounds read was addressed with improved input validation.
Bluetooth. A memory corruption issue was addressed with improved input validation.
libxml2. A buffer overflow was addressed with improved bounds checking.
libxml2. A buffer overflow was addressed with improved bounds checking.
libxml2. A buffer overflow was addressed with improved size validation.
TCC. A logic issue was addressed with improved restrictions.
An input validation issue was addressed with improved input validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafted web content may lead to a cross site scripting attack.
Bluetooth. A memory corruption issue was addressed with improved input validation.
Bluetooth. A memory corruption issue was addressed with improved input validation.
Time Machine. A logic issue was addressed with improved state management.
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3, watchOS 6.1.2. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
ImageIO. An out-of-bounds read was addressed with improved input validation.
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to read restricted memory.
AppleMobileFileIntegrity. This issue was addressed with improved checks.
FaceTime. A logic issue was addressed with improved state management.
Mail. An injection issue was addressed with improved validation.
autofs. This was addressed with additional checks by Gatekeeper on files mounted through a network share.
Kernel. A memory corruption issue was addressed with improved memory handling.