CVE-2020-10011: Apple iPadOS

High severity, CVSS 7.8. EPSS: 1.2% chance of exploitation in the next 30 days.

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 14.2 and iPadOS 14.2, macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

Affected products

  • Apple iPadOS: before 14.2 (fixed in 14.2)
  • Apple iPhone OS: before 14.2 (fixed in 14.2)
  • Apple Mac OS X: before 10.13.6 (fixed in 10.13.6); from 10.14, before 10.14.6 (fixed in 10.14.6); from 10.15, before 10.15.7 (fixed in 10.15.7); from 11.0.0, before 11.0.1 (fixed in 11.0.1); version 10.13.6 only; version 10.14.6 only; …
  • Apple tvOS: before 14.2 (fixed in 14.2)

Published 2020-12-08. Last modified 2026-06-17.