CVE-2020-27932
08.12.2020, 21:15
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to execute arbitrary code with kernel privileges.
| Vendor | Product | Version |
|---|---|---|
| apple | icloud | 𝑥 < 11.5 |
| apple | itunes | 𝑥 < 12.11 |
| apple | ipados | 𝑥 < 14.2 |
| apple | iphone_os | 𝑥 < 12.4.9 |
| apple | iphone_os | 14.0 ≤ 𝑥 < 14.2 |
| apple | mac_os_x | 𝑥 < 10.15.7 |
| apple | macos | 11.0 ≤ 𝑥 < 11.0.1 |
| apple | watchos | 𝑥 < 5.3.9 |
| apple | watchos | 6.0 ≤ 𝑥 < 6.2.9 |
| apple | watchos | 7.0 ≤ 𝑥 < 7.1 |
𝑥
= Vulnerable software versions
References