CVE-2020-13520: Apple macOS

High severity, CVSS 7.8. EPSS: 2.1% chance of exploitation in the next 30 days.

An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary USD files. A specially crafted malformed file can trigger an out of bounds memory modification which can result in remote code execution. To trigger this vulnerability, victim needs to access an attacker-provided malformed file.

Affected products

  • Apple macOS: before 11.1 (fixed in 11.1)
  • Pixar Openusd: version 20.05 only

Published 2020-12-11. Last modified 2026-06-17.