CVE-2020-9972: Apple Ipad OS

High severity, CVSS 7.8. EPSS: 1.4% chance of exploitation in the next 30 days.

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

Affected products

  • Apple Ipad OS: before 14.3 (fixed in 14.3)
  • Apple iPhone OS: before 14.3 (fixed in 14.3)
  • Apple macOS: before 11.1 (fixed in 11.1)
  • Apple tvOS: before 14.3 (fixed in 14.3)

Published 2020-12-08. Last modified 2026-06-17.