PT-2020-20837 · Apple · Apple Macos

Mickey Jin

·

Published

2020-09-16

·

Updated

2021-07-21

·

CVE-2020-9887

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apple macOS versions prior to 10.15.6
Description A memory corruption issue was addressed with improved input validation. Viewing a maliciously crafted JPEG file may lead to arbitrary code execution.
Recommendations For versions prior to 10.15.6, update to macOS Catalina 10.15.6 to resolve the issue. As a temporary workaround, consider avoiding viewing untrusted JPEG files until the update is applied.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9887
ZDI-20-1182

Affected Products

Apple Macos