CVE-2020-27909: Apple macOS AudioCodecs MP4 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.
Credit
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-27909.
What is the severity of CVE-2020-27909?
The severity of CVE-2020-27909 has not been disclosed.
Which software versions are affected by CVE-2020-27909?
Apple iOS up to version 14.2, Apple iPadOS up to version 14.2, Apple tvOS up to version 14.2, Apple macOS Big Sur up to version 11.0.1, and Apple watchOS up to version 7.1 are affected by CVE-2020-27909.
What is the updated version that addresses CVE-2020-27909?
The updated version that addresses CVE-2020-27909 is Apple iOS 14.2, Apple iPadOS 14.2, Apple tvOS 14.2, Apple macOS Big Sur 11.0.1, and Apple watchOS 7.1.
How can I fix CVE-2020-27909?
To fix CVE-2020-27909, update your Apple device to the latest available version: Apple iOS 14.2, Apple iPadOS 14.2, Apple tvOS 14.2, Apple macOS Big Sur 11.0.1, or Apple watchOS 7.1.