CVE-2020-27932 is a type confusion vulnerability affecting various Apple operating systems, including macOS, iOS, iPadOS, and watchOS. This flaw allows a malicious application to execute arbitrary code with kernel privileges due to improved state handling not being properly implemented. With a CVSS score of 7.8 (HIGH), it has a low attack complexity and requires user interaction, but can lead to complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog and multiple media reports detailing its use in zero-day attacks. Despite active exploitation, no public exploit code is available via Metasploit or ExploitDB, though it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.5CPE matchmatch criteria | cpe:2.3:a:apple:icloud:*:*:*:*:*:windows:*:* | ||
< 12.11CPE matchmatch criteria | cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:* | ||
< 14.2CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 12.4.9CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
>= 14.0, < 14.2CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.