A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
No PoCs from references.
- https://github.com/Charmve/BLE-Security-Attack-Defence
- https://github.com/hac425xxx/heap-exploitation-in-real-world
- https://github.com/houjingyi233/macOS-iOS-system-security