CVE-2020-27942: Apple Mac OS X

High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.

A logic issue was addressed with improved state management. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave. Processing a maliciously crafted font file may lead to arbitrary code execution.

Affected products

  • Apple Mac OS X: from 10.14, up to and including 10.14.5; from 10.15, up to and including 10.15.5; version 10.14.6 only; version 10.15.6 only; version 10.15.7 only

Published 2021-09-08. Last modified 2026-06-17.