Out-of-bounds read in iPadOS and Apple iOS - CVE-2020-27946
Published: December 15, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the FontParser component when processing fonts. A remote attacker can trick the victim into opening a file or web page that contains a specially crafted font, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Apple iOS
watchOS
macOS
tvOS
How to mitigate CVE-2020-27946
Apple iOS - update to 14.3 18C66
watchOS - update to 7.2 18S564
macOS - update to 11.1 20C69
tvOS - update to 14.3 18K561