CVE-2020-9990: Apple Mac OS X

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A race condition was addressed with additional validation. This issue is fixed in macOS Catalina 10.15.6. A malicious application may be able to execute arbitrary code with kernel privileges.

Affected products

  • Apple Mac OS X: before 10.5.6 (fixed in 10.5.6)

Published 2020-10-22. Last modified 2026-06-17.