A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Catalina 10.15.3. An application may be able to read restricted memory.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
APPLE-SA-2020-1-28-2 macOS Catalina 10153, Security Update
2020-001 Mojave, Security Update 2020-001 High Sierra
macOS Catalina 10153, Security Update 2020-001 Mojave, and
Security Update 2020-001 High Sierra are now available and
address the following:
AnnotationKit
Available for: macOS Catali ...