Logic Flaw in Apple Products Exposes Users to Code Execution Risks
CVE-2020-27942

7.8HIGH

Key Information:

Vendor
Apple
Vendor
CVE Published:
8 September 2021

Summary

A logic flaw in certain versions of macOS has been identified, which is linked to improper state management. This vulnerability allows processing of a specially crafted font file, potentially enabling an attacker to execute arbitrary code on the affected system. Users are advised to update to Security Update 2021-002 for Catalina and Security Update 2021-003 for Mojave to mitigate the risk associated with this vulnerability. Ensuring that your system is up to date is crucial for maintaining security and protecting against exploitation.

Affected Version(s)

Security Update - Catalina < 2021

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.