This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. Importing a maliciously crafted calendar invitation may exfiltrate user information.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/alphaSeclab/sec-daily-2020
- https://github.com/lnick2023/nicenice
- https://github.com/qazbnm456/awesome-cve-poc