High severity7.8NVD Advisory· Published Dec 8, 2020· Updated Jun 17, 2026
CVE-2020-27909
CVE-2020-27909
Description
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12unspecified+ 2 more
- (no CPE)range: unspecified
- cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*range: <7.1
- (no CPE)range: prior to 7.1
unspecified+ 2 more
- (no CPE)range: unspecified
- cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*range: <14.2
- (no CPE)range: prior to 14.2
- Range: unspecified
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <14.2
- (no CPE)range: prior to 14.2
- Range: prior to 14.2
Patches
Vulnerability mechanics
References
6- seclists.org/fulldisclosure/2020/Dec/32nvdMailing ListThird Party Advisory
- support.apple.com/en-us/HT211928nvdVendor Advisory
- support.apple.com/en-us/HT211929nvdVendor Advisory
- support.apple.com/en-us/HT211930nvdVendor Advisory
- support.apple.com/kb/HT211931nvdVendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-21-374/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.