CVE-2020-27948: High severity tvos vulnerability
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted audio file may lead to arbitrary code execution.
Other sources
CoreAudio. An out-of-bounds write issue was addressed with improved bounds checking.
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-29610
- CVE-2020-27948
- CVE-2020-29608
- CVE-2020-27946
- CVE-2020-27943
- CVE-2020-27944
- CVE-2020-29624
- CVE-2020-29615
- CVE-2020-29617
- CVE-2020-29619
- CVE-2020-29618
- CVE-2020-29611
- CVE-2020-29614
- CVE-2020-9972
- CVE-2020-29623
- CVE-2020-15969
- CVE-2021-31077
- CVE-2020-27914
- CVE-2020-27915
- CVE-2020-27936
- CVE-2020-27903
- CVE-2020-27941
- CVE-2020-29621
- CVE-2020-27910
- CVE-2020-9943
- CVE-2020-9944
- CVE-2020-27916
- CVE-2020-27906
- CVE-2020-27908
- CVE-2020-9960
- CVE-2020-10017
- CVE-2020-27922
- CVE-2020-10001
- CVE-2020-9962
- CVE-2020-27952
- CVE-2020-9956
- CVE-2020-27931
- CVE-2020-10002
- CVE-2020-27947
- CVE-2020-29612
- CVE-2020-9978
- CVE-2020-27939
- CVE-2020-29625
- CVE-2020-29616
- CVE-2020-27924
- CVE-2020-27912
- CVE-2020-27923
- CVE-2020-27919
- CVE-2020-10015
- CVE-2020-27897
- CVE-2020-27907
- CVE-2020-9974
- CVE-2020-10016
- CVE-2020-9967
- CVE-2020-9975
- CVE-2020-27921
- CVE-2020-27949
- CVE-2020-29620
- CVE-2020-27911
- CVE-2020-27920
- CVE-2020-27926
- CVE-2020-10014
- CVE-2020-10010
- CVE-2020-29633
- CVE-2020-13520
- CVE-2020-13524
- CVE-2020-10004
- CVE-2020-27901
- CVE-2020-27938
- CVE-2020-10007
- CVE-2020-10012
- CVE-2020-27896
- CVE-2020-10009
- CVE-2020-27898
- CVE-2020-27951
- CVE-2020-29613
Frequently Asked Questions
What is CVE-2020-27948?
CVE-2020-27948 is a vulnerability in CoreAudio that allows an attacker to perform an out-of-bounds write.
Which software versions are affected by CVE-2020-27948?
iOS 14.3, iPadOS 14.3, tvOS 14.3, macOS Big Sur up to version 11.1, Apple Catalina, Apple Mojave, and watchOS 7.2 are affected by CVE-2020-27948.
How can I fix CVE-2020-27948?
Apply the appropriate software update from Apple for your affected device.
Where can I find more information about CVE-2020-27948?
You can find more information about CVE-2020-27948 on the Apple support website.