ID:4674 - Exploit for Heap-based buffer overflow in macOS - CVE-2020-9856
Published: October 2, 2020
macOS
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the handling of Core Virtual Machine Service caches. A local user can pass specially crafted data to the applicatoin, trigger heap-based buffer overflow and execute arbitrary code on the target system with elevated privileges.