ZeroHour

CVE-2020-27930

KEVmass

Out-of-bounds write in Apple FontParser enables code execution on iOS, macOS, watchOS

CISA: Apple Multiple Products Memory Corruption Vulnerability

CVSS 3.1
7.8 high
EPSS
22%p98
Published
()
KEV added
AI analysis

CVE-2020-27930 is an out-of-bounds write (CWE-787) memory corruption flaw in the FontParser component used by Apple iOS, iPadOS, macOS, and watchOS. It is triggered when an application processes a maliciously crafted font, a file type commonly delivered remotely via web pages, email, documents, or messaging attachments. An attacker who successfully exploits it may achieve arbitrary code execution in the context of the application parsing the font. Any user of the affected Apple platforms running an unpatched OS version is potentially exposed, because font parsing is a core, remotely reachable code path. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating confirmed exploitation in the wild; no public proof-of-concept is known, CVSS is not yet scored, and EPSS ranks it in the 98th percentile with a 22% probability of exploitation within 30 days.

What to do: Apply Apple's OS updates for iOS, iPadOS, macOS, and watchOS that remediate CVE-2020-27930 per vendor instructions, prioritizing devices that render untrusted content and user workstations; as a KEV entry, federal agencies must patch by the catalog deadline. Until patched, reduce exposure by treating untrusted fonts as attack surface (avoid opening suspicious documents/attachments and remote content) and verify OS versions across your fleet with device management tooling.

Affected
Apple iOS (FontParser component)
Apple iPadOS (FontParser component)
Apple macOS (FontParser component)
Apple watchOS (FontParser component)
Estimated exposure
masshundreds of millions to 1B+ unpatched Apple devices (vendor's active installed base exceeds 1 billion devices) — Apple's publicly reported active installed base of iOS, iPadOS, macOS, and watchOS devices exceeds one billion, and FontParser is a core OS component present on all of them, so exposure is bounded only by patch uptake; the exact count of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processing a maliciously crafted font may lead to arbitrary code execution.

CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
apple
Products
ipados, iphone os, mac os x, macos, watchos
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news