Apple Security Advisories · November 2020 — Apple Security Advisories
57 advisories 57 CVEs 3 EXPLOITED

Apple-vendor CVEs for 2020-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2020-27930

iPadOSExploitedCISA KEV listedCRITICAL2020-11-06

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2...

CVEs:CVE-2020-27930

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2020-27950

iPadOSExploitedCISA KEV listedHIGH2020-11-06

A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Cata...

CVEs:CVE-2020-27950

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27932

iPadOSExploitedCISA KEV listedHIGH2020-11-06

A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, wat...

CVEs:CVE-2020-27932

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
macos affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2020-9999

macOSPoC exploitCRITICAL2020-11-13

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iTunes for Windows 12.10.9. Processing a maliciously crafted text file may lead to arbitrary code execution.

CVEs:CVE-2020-9999

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27904

macOSPoC exploitHIGH2020-11-13

A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-27904

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2020-25709

OtherPoC exploitHIGH2020-11-17

A flaw was found in OpenLDAP. This flaw allows an attacker who can send a malicious packet to be processed by OpenLDAP’s slapd server, to trigger an assertion failure. The highest threat from this vulnerability is to system availability.

CVEs:CVE-2020-25709

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-27911

iPadOSEPSS <= 49%HIGH2020-11-06

An integer overflow was addressed through improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. A remote attacker may be able to caus...

CVEs:CVE-2020-27911

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-8037

OtherEPSS <= 49%HIGH2020-11-04

The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.

CVEs:CVE-2020-8037

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-27906

macOSEPSS <= 49%HIGH2020-11-13

Multiple integer overflows were addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1. A remote attacker may be able to cause unexpected application termination or heap corruption.

CVEs:CVE-2020-27906

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2020-9991

iPadOSEPSS <= 49%HIGH2020-11-13

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iCloud for Windows 7.21, tvOS 14.0. A remote attacker may be able to cause a denial of service.

CVEs:CVE-2020-9991

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27909

iPadOSEPSS <= 49%HIGH2020-11-06

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.

CVEs:CVE-2020-27909

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9849

iPadOSEPSS <= 49%HIGH2020-11-13

An information disclosure issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS 14.0. A remote attacker may be a...

CVEs:CVE-2020-9849

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
itunes affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27912

iPadOSEPSS <= 49%HIGH2020-11-06

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. Processing a maliciously crafted imag...

CVEs:CVE-2020-27912

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27917

iPadOSEPSS <= 49%HIGH2020-11-06

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web c...

CVEs:CVE-2020-27917

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-10016

iPadOSEPSS <= 49%HIGH2020-11-06

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-10016

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27910

iPadOSEPSS <= 49%HIGH2020-11-06

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.

CVEs:CVE-2020-27910

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27916

iPadOSEPSS <= 49%HIGH2020-11-06

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.

CVEs:CVE-2020-27916

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-6147

OtherEPSS <= 49%CRITICAL2020-11-13

A heap overflow vulnerability exists in Pixar OpenUSD 20.05 when the software parses compressed sections in binary USD files. This instance exists in the USDC file format FIELDS section decompression heap overflow.

CVEs:CVE-2020-6147

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2020-9861

OtherEPSS <= 49%CRITICAL2020-11-02

A stack overflow issue existed in Swift for Linux. The issue was addressed with improved input validation for dealing with deeply nested malicious JSON input.

CVEs:CVE-2020-9861

Affected products

ProductStatusVendorPackageEcosystem
swift affected apple
Upstream advisory

CVE-2020-9949

iPadOSEPSS <= 49%HIGH2020-11-13

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra, tvO...

CVEs:CVE-2020-9949

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27896

macOSEPSS <= 49%MEDIUM2020-11-13

A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1. A remote attacker may be able to modify the file system.

CVEs:CVE-2020-27896

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-9965

iPadOSEPSS <= 49%HIGH2020-11-13

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-9965

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-10017

iPadOSEPSS <= 49%CRITICAL2020-11-06

An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.

CVEs:CVE-2020-10017

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-10004

iPadOSEPSS <= 49%CRITICAL2020-11-06

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2. Opening a maliciously crafted file may lead to unexpected application termination or arbitrary code execution.

CVEs:CVE-2020-10004

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2020-27918

iPadOSEPSS <= 49%CRITICAL2020-11-06

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciousl...

CVEs:CVE-2020-27918

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
macos affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27905

iPadOSEPSS <= 49%HIGH2020-11-06

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A malicious application may be able to execute arbitrary code with system privileges.

CVEs:CVE-2020-27905

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27927

iPadOSEPSS <= 49%CRITICAL2020-11-06

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted font file may lead to arbitrary code execution.

CVEs:CVE-2020-27927

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
macos affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9966

iPadOSEPSS <= 49%CRITICAL2020-11-13

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-9966

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9974

iPadOSEPSS <= 49%MEDIUM2020-11-06

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A malicious application may be able to determine kernel memory layout.

CVEs:CVE-2020-9974

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9942

macOSEPSS <= 49%MEDIUM2020-11-13

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, Safari 13.1.2. Visiting a malicious website may lead to address bar spoofing.

CVEs:CVE-2020-9942

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
safari affected apple
Upstream advisory

CVE-2020-9945

macOSEPSS <= 49%MEDIUM2020-11-13

A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, Safari 14.0.1. Visiting a malicious website may lead to address bar spoofing.

CVEs:CVE-2020-9945

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
safari affected apple
Upstream advisory

CVE-2020-10011

iPadOSEPSS <= 49%CRITICAL2020-11-06

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. Processing a maliciously crafted USD file...

CVEs:CVE-2020-10011

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
Upstream advisory

CVE-2020-27903

macOSEPSS <= 49%HIGH2020-11-13

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Big Sur 11.0.1. An application may be able to gain elevated privileges.

CVEs:CVE-2020-27903

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2020-9943

iPadOSEPSS <= 49%MEDIUM2020-11-13

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. A malicious application may be able to read restricted memory.

CVEs:CVE-2020-9943

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9944

iPadOSEPSS <= 49%MEDIUM2020-11-13

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to read restricted memory.

CVEs:CVE-2020-9944

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-27926

iPadOSEPSS <= 49%HIGH2020-11-06

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.2 and iPadOS 14.2. Processing maliciously crafted web content may lead to arbitrary code execution.

CVEs:CVE-2020-27926

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2020-10014

macOSEPSS <= 49%MEDIUM2020-11-13

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to break out of its sandbox.

CVEs:CVE-2020-10014

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-10009

macOSEPSS <= 49%MEDIUM2020-11-13

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A sandboxed process may be able to circumvent sandbox restrictions.

CVEs:CVE-2020-10009

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-10012

macOSEPSS <= 49%CRITICAL2020-11-13

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Big Sur 11.0.1. Processing a maliciously crafted document may lead to a cross site scripting attack.

CVEs:CVE-2020-10012

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-27898

macOSEPSS <= 49%HIGH2020-11-13

A denial of service issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1. An attacker may be able to bypass Managed Frame Protection.

CVEs:CVE-2020-27898

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2020-9963

iPadOSEPSS <= 49%MEDIUM2020-11-13

The issue was addressed with improved handling of icon caches. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A malicious app may be able to determine the existence of files on the computer.

CVEs:CVE-2020-9963

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-27900

macOSEPSS <= 49%MEDIUM2020-11-13

An issue existed in the handling of snapshots. The issue was resolved with improved permissions logic. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to preview files it does not have access to.

CVEs:CVE-2020-27900

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2020-9977

iPadOSEPSS <= 49%MEDIUM2020-11-13

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A malicious application may be able to dete...

CVEs:CVE-2020-9977

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-10006

macOSEPSS <= 49%MEDIUM2020-11-13

This issue was addressed with improved entitlements. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to access restricted files.

CVEs:CVE-2020-10006

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-9996

iPadOSEPSS <= 49%CRITICAL2020-11-13

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A malicious application may be able to elevate privileges.

CVEs:CVE-2020-9996

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-13524

OtherEPSS <= 49%HIGH2020-11-06

An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially crafted malformed file can trigger an out-of-bounds memory access and modification which results in memory corrupt...

CVEs:CVE-2020-13524

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-27894

macOSEPSS <= 49%MEDIUM2020-11-13

The issue was addressed with additional user controls. This issue is fixed in macOS Big Sur 11.0.1. Users may be unable to remove metadata indicating where files were downloaded from.

CVEs:CVE-2020-27894

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2020-27929

iOSEPSS <= 49%MEDIUM2020-11-06

A logic issue existed in the handling of Group FaceTime calls. The issue was addressed with improved state management. This issue is fixed in iOS 12.4.9. A user may send video in Group FaceTime calls without knowing that they have done so.

CVEs:CVE-2020-27929

Affected products

ProductStatusVendorPackageEcosystem
iphone_os affected apple
Upstream advisory

CVE-2020-10010

iPadOSEPSS <= 49%HIGH2020-11-06

A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A local attacker may be able to elevate their privileges.

CVEs:CVE-2020-10010

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-10002

iPadOSEPSS <= 49%MEDIUM2020-11-06

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, tvOS 14.2, iTunes 12.11 for Windows. A local user may be able to read arbitrary files.

CVEs:CVE-2020-10002

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-10003

iPadOSEPSS <= 49%HIGH2020-11-06

An issue existed within the path validation logic for symlinks. This issue was addressed with improved path sanitization. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A local attacker may be able to ele...

CVEs:CVE-2020-10003

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-10007

macOSEPSS <= 49%MEDIUM2020-11-13

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to determine kernel memory layout.

CVEs:CVE-2020-10007

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-9969

iPadOSEPSS <= 49%MEDIUM2020-11-13

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. A local user may be able to view senstive user information.

CVEs:CVE-2020-9969

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9989

iPadOSEPSS <= 49%MEDIUM2020-11-13

The issue was addressed with improved deletion. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A local user may be able to discover a user’s deleted messages.

CVEs:CVE-2020-9989

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2020-9988

iPadOSEPSS <= 49%MEDIUM2020-11-13

The issue was addressed with improved deletion. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A local user may be able to discover a user’s deleted messages.

CVEs:CVE-2020-9988

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-27902

iPadOSEPSS <= 49%MEDIUM2020-11-06

An authentication issue was addressed with improved state management. This issue is fixed in iOS 14.2 and iPadOS 14.2. A person with physical access to an iOS device may be able to access stored passwords without authentication.

CVEs:CVE-2020-27902

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2020-27925

iPadOSEPSS <= 49%HIGH2020-11-06

An issue existed in the handling of incoming calls. The issue was addressed with additional state checks. This issue is fixed in iOS 14.2 and iPadOS 14.2. A user may answer two calls simultaneously without indication they have answered a second call.

CVEs:CVE-2020-27925

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.