CVE-2020-27930
KEVmassOut-of-bounds write in Apple FontParser enables code execution on iOS, macOS, watchOS
CISA: Apple Multiple Products Memory Corruption Vulnerability
CVE-2020-27930 is an out-of-bounds write (CWE-787) memory corruption flaw in the FontParser component used by Apple iOS, iPadOS, macOS, and watchOS. It is triggered when an application processes a maliciously crafted font, a file type commonly delivered remotely via web pages, email, documents, or messaging attachments. An attacker who successfully exploits it may achieve arbitrary code execution in the context of the application parsing the font. Any user of the affected Apple platforms running an unpatched OS version is potentially exposed, because font parsing is a core, remotely reachable code path. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating confirmed exploitation in the wild; no public proof-of-concept is known, CVSS is not yet scored, and EPSS ranks it in the 98th percentile with a 22% probability of exploitation within 30 days.
What to do: Apply Apple's OS updates for iOS, iPadOS, macOS, and watchOS that remediate CVE-2020-27930 per vendor instructions, prioritizing devices that render untrusted content and user workstations; as a KEV entry, federal agencies must patch by the catalog deadline. Until patched, reduce exposure by treating untrusted fonts as attack surface (avoid opening suspicious documents/attachments and remote content) and verify OS versions across your fleet with device management tooling.
| Apple iOS (FontParser component) | — |
| Apple iPadOS (FontParser component) | — |
| Apple macOS (FontParser component) | — |
| Apple watchOS (FontParser component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processing a maliciously crafted font may lead to arbitrary code execution.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- ipados, iphone os, mac os x, macos, watchos
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H