An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to execute arbitrary code with kernel privileges.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://support.apple.com/en-us/HT211843 | vendor advisory |
https://support.apple.com/en-us/HT211850 | vendor advisory |
https://support.apple.com/en-us/HT211844 | vendor advisory |
https://support.apple.com/en-us/HT211931 | vendor advisory |
http://seclists.org/fulldisclosure/2020/Dec/32 | third party advisory mailing list |