LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-27950: Apple Multiple Products Memory Initialization Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
CVSS 5.5 · Medium⚠ Actively exploited (CISA KEV)
5.5
CVSS score
Medium
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-27950 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory.

CVE-2020-27950 is a memory initialization vulnerability affecting multiple Apple products, including iOS, iPadOS, macOS, and watchOS. A malicious application may be able to disclose kernel memory. For defenders, this matters because kernel memory disclosure can leak sensitive system information that helps an attacker better understand or further compromise a device. Confirm exact product coverage and fixed builds against the vendor advisory.

How it works

This issue is classed as CWE-665 (Improper Initialization). In general terms for this weakness, memory is used or exposed before it has been properly initialized, so residual or unintended contents may become readable. According to the CISA summary, the flaw may allow a malicious application to disclose kernel memory on affected Apple platforms.

An attacker would need to run a malicious application in a position to trigger the vulnerable path. Public detail in the provided record does not describe exact trigger conditions, APIs, or exploit mechanics; treat any deeper technical claims as unconfirmed unless they appear in Apple’s advisory. Kernel memory disclosure does not by itself equal full device takeover, but it can reduce the difficulty of follow-on attacks if other weaknesses are present. Ransomware use is not documented for this CVE in the given facts.

Am I affected? How to find it in your systems

Affected software is reported as Apple iOS, iPadOS, macOS, and watchOS. These run on iPhones, iPads, Macs, and Apple Watches commonly found on corporate and BYOD fleets, executive devices, and lab or kiosk hardware.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Deploy the Apple security updates that address CVE-2020-27950 on all eligible iOS, iPadOS, macOS, and watchOS devices as soon as your testing process allows.

Exact package names and build numbers must be taken from Apple’s advisory; do not rely on third-party version lists alone.

If you can't patch immediately

Reduce exposure until updates can be applied:

Compensating controls lower risk; they do not replace the vendor update.

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and data exposure even when ransomware use is not documented. If you suspect malicious applications ran on vulnerable devices, follow your incident process: isolate affected endpoints, preserve logs and crash data, rotate credentials accessible from those devices, and assess what kernel-level or app data might have been readable. You can run a free exposure scan of your email addresses to check whether those identities appear in known breach datasets and prioritize password and session resets accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
WeaknessCWE-665
CVSS base score5.5 (Medium)
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
PublishedDec 8, 2020
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities