CVE-2020-13495
Description
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially crafted malformed file can trigger an arbitrary out-of-bounds memory access that could lead to the disclosure of sensitive information. This vulnerability could be used to bypass mitigations and aid additional exploitation. To trigger this vulnerability, the victim needs to access an attacker-provided file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds memory access in Pixar OpenUSD 20.05 when parsing malformed binary USD files can lead to information disclosure.
Vulnerability
An exploitable vulnerability exists in Pixar OpenUSD 20.05 in the way it handles file offsets in binary USD files. The _ReadTOC function reads a table of contents offset from the file's bootstrap without proper bounds checking, allowing an attacker to craft a malformed file that triggers an arbitrary out-of-bounds memory access [1]. The affected version is OpenUSD 20.05, as tested on macOS Catalina 10.15.3.
Exploitation
An attacker can create a specially crafted binary USD file with manipulated file offsets. The victim must open the malicious file, for example by viewing a thumbnail on macOS or opening a shared file via iMessage on iOS. No authentication is required, but user interaction is necessary [1].
Impact
Successful exploitation results in an out-of-bounds read, leading to the disclosure of sensitive information from memory. This information disclosure could be used to bypass security mitigations and aid in further exploitation. The CVSSv3 score is 4.3, indicating low confidentiality impact [1].
Mitigation
The available reference does not specify a fixed version or workaround. Users should monitor Pixar OpenUSD for updates and apply any patches when released. Until a fix is available, avoid opening untrusted USD files [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: Catalina 10.15.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- talosintelligence.com/vulnerability_reports/TALOS-2020-1104mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.