Type Confusion in macOS - CVE-2020-27932

 

Type Confusion in macOS - CVE-2020-27932

Published: November 6, 2020


Vulnerability identifier: #VU48172
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27932
CWE-ID: CWE-843
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a type confusion error in macOS kernel. A local user can run a specially crafted application to trigger a type confusion error and execute arbitrary code with elevated privileges.

Note, this vulnerability is being actively exploited in the wild.


Affected software

macOS
watchOS
Apple iOS
iPadOS

How to mitigate CVE-2020-27932

Install updates from vendor's website.

macOS - update to 10.15.7 19H15
watchOS - addressed in versions 5.3.9, 6.2.9, 7.1 18R590
Apple iOS - addressed in versions 12.4.9 16H5, 14.2 18B92
iPadOS - update to 14.2 18B92

External References

Related Security Bulletins