#VU28309 Heap-based buffer overflow in macOS - CVE-2020-9856
Published: May 28, 2020 / Updated: October 2, 2020
macOS
Apple Inc.
Description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the handling of Core Virtual Machine Service caches. A local user can pass specially crafted data to the applicatoin, trigger heap-based buffer overflow and execute arbitrary code on the target system with elevated privileges.