| CVE ID | Vulnerability | Impact |
| CVE-2020-10002 | A logic issue was addressed with improved state management | Access to read arbitrary files |
| CVE-2020-27912 | An out-of-bounds write was addressed with improved input validation | Arbitrary code execution |
| CVE-2020-27917 | A use after free issue was addressed with improved memory management | Arbitrary code execution |
| CVE-2020-27911 | An integer overflow was addressed through improved input validation | Unexpected application termination |
| CVE-2020-27918 | A use after free issue was addressed with improved memory management | Arbitrary code execution |
| CVE-2020-27895 | An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling | Access to local user's Apple IDs |