CVE-2020-13524: Apple Mac OS X

Medium severity, CVSS 5.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An out-of-bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 uses SPECS data from binary USD files. A specially crafted malformed file can trigger an out-of-bounds memory access and modification which results in memory corruption. To trigger this vulnerability, the victim needs to access an attacker-provided malformed file.

Affected products

  • Apple Mac OS X: from 10.14.0, before 10.14.6 (fixed in 10.14.6); from 10.15, before 10.15.7 (fixed in 10.15.7); version 10.14.6 only; version 10.15.7 only
  • Apple macOS: from 11.0, before 11.1 (fixed in 11.1)
  • Pixar Openusd: version 20.05 only

Published 2020-12-03. Last modified 2026-06-17.