LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-27930: Apple Multiple Products Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-27930 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Apple iOS, iPadOS, macOS, and watchOS FontParser contain a memory corruption vulnerability which may allow for code execution when processing maliciously crafted front.

CVE-2020-27930 is a memory corruption vulnerability in the FontParser component of Apple iOS, iPadOS, macOS, and watchOS. Processing a maliciously crafted font can allow an attacker to achieve code execution on the device. This matters because fonts are routinely handled by the operating system during everyday activities such as viewing documents or web content, giving the flaw a practical path into user and enterprise devices if left unpatched.

CISA lists the required action as applying updates per vendor instructions. Ransomware use is not documented for this CVE. Confirm all product-specific details against the official Apple advisory.

How it works

The weakness is classified as CWE-787 (out-of-bounds write). FontParser fails to handle certain malformed font data safely, resulting in memory corruption. An attacker who can supply a crafted font file—commonly delivered through a document, web page, or other content the device will parse—can trigger the corruption. Successful exploitation may allow arbitrary code execution in the context of the vulnerable process.

Exact exploit mechanics, required user interaction, and privilege levels are not detailed in the provided facts; treat any public proof-of-concept claims cautiously and validate against the vendor advisory. The core risk is that font parsing is a common, often automatic operation, so the attack surface is broader than features users consciously enable.

Am I affected? How to find it in your systems

The vulnerability affects Apple iOS, iPadOS, macOS, and watchOS systems that include the vulnerable FontParser component. These platforms appear on phones, tablets, laptops, desktops, and watches used by employees and in managed fleets.

If your inventory tooling cannot query OS build levels, treat devices that have not received recent Apple security updates as potentially exposed until verified.

How to remediate

Patch first. Apply the security updates Apple released for the affected products, following the vendor’s instructions exactly. Use MDM or automated update mechanisms to drive installation and verify successful application via version inventory.

Confirm the precise update names and build numbers in Apple’s advisory; do not assume a generic “latest OS” status is sufficient without checking.

If you can't patch immediately

Implement compensating controls while you schedule the update:

These measures reduce likelihood and impact but do not eliminate the vulnerability; patching remains the definitive fix.

If your data may have been exposed

Actively exploited memory-corruption vulnerabilities can lead to device compromise and subsequent data theft. If you have indicators of exploitation or unpatched devices that handled untrusted content, follow your incident-response process: isolate affected endpoints, preserve logs and memory images, rotate credentials accessible from those devices, and assess what data may have been reachable. Ransomware use is not documented for this CVE, but any code-execution foothold warrants full investigation. You can run a free exposure scan of your email addresses against known breach data sets to check whether associated credentials or personal information have appeared in prior incidents, then force password resets and enable stronger authentication where matches are found.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
WeaknessCWE-787
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities