CVE-2020-27945: Apple Mac OS X

High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.0.1. Processing maliciously crafted web content may lead to arbitrary code execution.

Affected products

  • Apple Mac OS X: from 10.14, before 10.14.6 (fixed in 10.14.6); from 10.15, before 10.15.7 (fixed in 10.15.7); version 10.14.6 only; version 10.15.7 only
  • Apple macOS: from 11.0, before 11.2.0 (fixed in 11.2.0)

Published 2021-04-02. Last modified 2026-06-17.