cbcvebase.
CVE-2020-27932
published 2020-12-08

CVE-2020-27932: A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9…

PriorityP182high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
10.34%
95.2th percentile
A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to execute arbitrary code with kernel privileges.

Affected

19 ranges
VendorProductVersion rangeFixed in
appleicloud< 11.511.5
appleios_14.2_and_ipados
appleios_and_ipados>= unspecified < 14.214.2
appleipados< 14.214.2
appleiphone_os< 12.4.912.4.9
appleiphone_os>= 14.0 < 14.214.2
appleitunes< 12.1112.11
applemac_os_x< 10.15.710.15.7
applemacos>= 11.0 < 11.0.111.0.1
applemacos>= unspecified < 11.011.0
applemacos>= unspecified < 12.412.4
applemacos>= unspecified < 6.26.2
applemacos>= unspecified < 5.35.3
applemacos>= unspecified < 20202020
applemacos>= unspecified < 10.1510.15
applewatchos< 5.3.95.3.9
applewatchos>= 6.0 < 6.2.96.2.9
applewatchos>= 7.0 < 7.17.1
applewatchos>= unspecified < 7.17.1

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is confirmed exploited in the wild (ITW); prioritize detection of exploitation attempts targeting the XNU kernel via malicious applications on Apple platforms (iOS, iPadOS, macOS, watchOS)
  • Focus on kernel-level privilege escalation from a sandboxed/malicious application context — the exploit chain involves a type confusion in the Kernel component leading to arbitrary code execution with kernel privileges
  • The root cause is a type confusion issue in the Kernel component; hunt for anomalous kernel memory access patterns or unexpected kernel privilege grants originating from user-space applications on affected Apple OS versions
  • ·Affected platforms span multiple Apple OS families and versions; ensure detection/patching scope covers all: macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2, iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update
  • ·CISA KEV-listed with a mandated remediation due date of 2022-05-03; treat as actively exploited and high-priority for patching and detection

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck8.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.