First published: Tue Jan 28 2020(Updated: )
The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with system privileges.
Credit: Dayton Pidhirney @_watbulb Dayton Pidhirney @_watbulb Dayton Pidhirney @_watbulb Dayton Pidhirney @_watbulb Dayton Pidhirney @_watbulb Dayton Pidhirney @_watbulb product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple tvOS | <13.3.1 | 13.3.1 |
Apple iOS | <13.3.1 | 13.3.1 |
Apple iPadOS | <13.3.1 | 13.3.1 |
Apple macOS Catalina | <10.15.3 | 10.15.3 |
Apple Mojave | ||
Apple High Sierra | ||
Apple watchOS | <6.1.2 | 6.1.2 |
Apple Catalina | ||
Apple iPadOS | <13.3.1 | |
Apple iPhone OS | <13.3.1 | |
Apple Mac OS X | <10.14.6 | |
Apple Mac OS X | >=10.15<10.15.3 | |
Apple Mac OS X | =10.14.6 | |
Apple Mac OS X | =10.14.6-security_update_2019-001 | |
Apple Mac OS X | =10.14.6-security_update_2019-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-001 | |
Apple Mac OS X | =10.14.6-security_update_2020-002 | |
Apple Mac OS X | =10.14.6-security_update_2020-003 | |
Apple Mac OS X | =10.14.6-security_update_2020-004 | |
Apple Mac OS X | =10.14.6-security_update_2020-005 | |
Apple Mac OS X | =10.14.6-security_update_2020-006 | |
Apple Mac OS X | =10.14.6-security_update_2020-007 | |
Apple Mac OS X | =10.14.6-security_update_2021-001 | |
Apple Mac OS X | =10.14.6-security_update_2021-002 | |
Apple Mac OS X | =10.14.6-supplemental_update | |
Apple Mac OS X | =10.14.6-supplemental_update_2 | |
Apple tvOS | <13.3.1 | |
Apple watchOS | <6.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2020-3838.
The affected software includes Apple Catalina, Apple Mojave, Apple macOS Catalina (up to version 10.15.3), Apple High Sierra, Apple watchOS (up to version 6.1.2), Apple iOS (up to version 13.3.1), Apple iPadOS (up to version 13.3.1), and Apple tvOS (up to version 13.3.1).
The severity level of this vulnerability is not provided.
This vulnerability was addressed with improved permissions logic.
You can find more information about this vulnerability at the following references: [1](https://support.apple.com/en-us/HT210920), [2](https://support.apple.com/en-us/HT212326), [3](https://support.apple.com/en-us/HT212327).