CVE-2020-27949

MEDIUM

macOS 10.14-10.14.5 and 11.0 - Unauthorized Memory Modification via DTrace

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-27949. PoCs published by seemoo-lab.

AI-analyzed exploit summary This PoC exploits CVE-2020-27949, a vulnerability in macOS's `/dev/fasttrap` device, allowing arbitrary memory read/write in processes running under DTrace without elevated permissions. The exploit leverages `FASTTRAPIOC_MAKEPROBE` and `FASTTRAPIOC_GETINSTR` ioctls to replace memory values with trap instructions and dump memory contents.

Description

This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may cause unexpected changes in memory belonging to processes traced by DTrace.

Exploits (1)

nomisec WORKING POC 35 stars
by seemoo-lab · poc
https://github.com/seemoo-lab/dtrace-memaccess_cve-2020-27949

This PoC exploits CVE-2020-27949, a vulnerability in macOS's `/dev/fasttrap` device, allowing arbitrary memory read/write in processes running under DTrace without elevated permissions. The exploit leverages `FASTTRAPIOC_MAKEPROBE` and `FASTTRAPIOC_GETINSTR` ioctls to replace memory values with trap instructions and dump memory contents.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: macOS (versions prior to Big Sur 11.1, Catalina 2020-001, Mojave 2020-007)
No auth needed
Prerequisites: Victim process must be running under DTrace · Attacker must have execution permissions on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/en-us/HT212011

Scores

CVSS v3 5.5
EPSS 0.0022
EPSS Percentile 43.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

Status published
Products (4)
apple/mac_os_x 10.14.6 (13 CPE variants)
apple/mac_os_x 10.15.7 (2 CPE variants)
apple/mac_os_x 10.14 - 10.14.6
apple/macos 11.0 - 11.1.0
Published Apr 02, 2021
Tracked Since Feb 18, 2026