CVE-2020-27942
Description
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Processing a maliciously crafted font file may lead to arbitrary code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A logic issue in macOS font parsing allows arbitrary code execution via a maliciously crafted font file. Fixed in Security Update 2021-002 Catalina and Security Update 2021-003 Mojave.
Vulnerability
A logic issue in the font file parsing component of macOS allows an attacker to trigger arbitrary code execution. The vulnerability is reachable by processing a maliciously crafted font file. The issue affects macOS Catalina and Mojave and is addressed in Security Update 2021-002 Catalina and Security Update 2021-003 Mojave [1][2].
Exploitation
An attacker can exploit this vulnerability by delivering a specially crafted font file to a target system, for example via a web page, email attachment, or other means that cause the font to be loaded. No additional privileges or authentication beyond the ability to trigger font parsing are required. The attacker does not need local access; the exploit can be triggered remotely if the victim processes the malicious font (e.g., visiting a website that loads the crafted font).
Impact
Successful exploitation leads to arbitrary code execution with the privileges of the affected process (e.g., a browser or system service). This can result in full compromise of the user's system, including data exfiltration, installation of malware, or further lateral movement.
Mitigation
Apple released Security Update 2021-002 for macOS Catalina and Security Update 2021-003 for macOS Mojave on April 26, 2021, which fix this vulnerability [1][2]. Users should install the appropriate security update immediately. No workaround is available; the vulnerability is only mitigated by installing the patch.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- support.apple.com/en-us/HT212326mitrex_refsource_MISC
- support.apple.com/en-us/HT212327mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.