ZeroHour
Security Affairspublished ()ingested @securityaffairs

Apple addressed multiple code execution flaws in iOS and iPadOS

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-27944
+1 in the same advisory: …27943
A memory corruption issue existed in the processing of font files.

A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted font file may lead to arbitrary code execution.

NVD description · AI analysis pending
7.81%
  • apple ipad os
  • apple iphone os
  • apple macos
  • +1 more
CVE-2020-29618
+2 in the same advisory: …29617 …29619
An out-of-bounds read was addressed with improved input validation.

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to arbitrary code execution.

NVD description · AI analysis pending
7.81%
  • apple icloud
  • apple ipados
  • apple iphone os
  • +1 more
Full article248 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 15, 2020

Apple addressed this week serious code execution vulnerabilities that affect its iOS and iPadOS mobile operating systems.

Apple released security updates to fix multiple severe code execution vulnerabilities in its iOS and iPadOS mobile operating systems.

The IT giant released iOS 14.3 and iPadOS 14.3 version to address eleven security vulnerabilities, including code execution flaws.

The most serious issue could be exploited by an attacker to execute malicious code on Apple iPhones and iPads via a malicious font file. The vendor fixed two font parsing issues tracked CVE-2020-27943 and CVE-2020-27944. 

“Processing a maliciously crafted font file may lead to arbitrary code execution.” reads the security advisory publishes by Apple.

“A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation.”

Apple also patched two memory corruption flaws that reside in the way input in certain font files is validated, threat actors could exploit them to achieve arbitrary code execution.

The company fixed three separate security bugs (CVE-2020-29617, CVE-2020-29618, CVE-2020-29619) that affect the ImageIO programming interface framework and which could be exploited to execute arbitrary code via specially-crafted images.    

The company also addressed an out-of-bounds write issue that may lead to arbitrary code execution by processing a maliciously crafted audio file.

Apple finally fixed a logic issue in App Store that can lead enterprise application installation into displaying the wrong domain.

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, iPhones)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/112304/security/ios-ipados-flaws.html