CVE-2020-27932
KEVmassKernel Type Confusion in Apple iOS, macOS, watchOS Allows Code Execution (CVE-2020-27932)
CISA: Apple Multiple Products Type Confusion Vulnerability
CVE-2020-27932 is a type confusion flaw (CWE-843) in the kernel of Apple's iPhone/iPad OS, macOS, and watchOS, addressed with improved state handling in Apple's November 2020 security releases. It is triggered when a malicious (or compromised) application already running on the device sends input that confuses object types in kernel state handling — the attack is local and requires the user to run the app. A successful attacker gains arbitrary code execution with kernel privileges, the highest privilege level on the device, enabling full device control, persistence, and access to sensitive data. Anyone running unpatched iPhones, iPads, Macs, or Apple Watches is affected, and the CISA data also lists iCloud and iTunes among the affected Apple products. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with an EPSS of ~10.3% (95th percentile), and related reporting ties it to exploit kits (Coruna, DarkSword) used by a threat actor deploying roughly 11 zero-days against iOS 13 devices, so exploitation in the wild is established.
What to do: Patch immediately: update to iOS/iPadOS 14.2 (or iOS 12.4.9 for older devices), macOS Big Sur 11.0.1, macOS Catalina 10.15.7 Supplemental Update, or Security Update 2020-006 (High Sierra/Mojave), and watchOS 7.1/6.2.9/5.3.9; also update iCloud and iTunes for Windows per Apple's advisory. Because exploitation in the wild is confirmed and exploit kits targeting iOS 13 are reported, audit Apple endpoints for signs of compromise and ensure users install apps only from trusted sources until patched.
| Apple iPhone OS / iOS | versions prior to iOS 14.2; older devices fixed in iOS 12.4.9 |
| Apple iPadOS | versions prior to iPadOS 14.2 |
| Apple macOS (incl. Mac OS X) | versions prior to macOS Big Sur 11.0.1, macOS Catalina 10.15.7 (Supplemental) Update, Security Update 2020-006 High Sierra, and Security Update 2020-006 Mojave |
| Apple watchOS | versions prior to watchOS 7.1; older devices fixed in watchOS 6.2.9 and watchOS 5.3.9 |
| Apple iCloud | versions fixed per Apple's November 2020 security updates (see vendor advisory for exact fixed version) |
| Apple iTunes | versions fixed per Apple's November 2020 security updates (see vendor advisory for exact fixed version) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to execute arbitrary code with kernel privileges.
- Affected
- Apple Multiple Products
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- apple
- Products
- icloud, itunes, ipados, iphone os, mac os x, macos, watchos
- Weakness
- CWE-843
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H