First published: Tue Jan 28 2020(Updated: )
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to read restricted memory.
Credit: Haakon Garseg Mørk CogniteCim Stordal CogniteHaakon Garseg Mørk CogniteCim Stordal CogniteHaakon Garseg Mørk CogniteCim Stordal CogniteHaakon Garseg Mørk CogniteCim Stordal Cognite product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple tvOS | <13.3.1 | 13.3.1 |
Apple iOS | <13.3.1 | 13.3.1 |
Apple iPadOS | <13.3.1 | 13.3.1 |
Apple macOS Catalina | <10.15.3 | 10.15.3 |
Apple Mojave | ||
Apple High Sierra | ||
Apple watchOS | <6.1.2 | 6.1.2 |
Apple iPadOS | <13.3.1 | |
Apple iPhone OS | <13.3.1 | |
Apple Mac OS X | <10.15.3 | |
Apple tvOS | <13.3.1 | |
Apple watchOS | <6.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-3872 is a vulnerability in the kernel that relates to a memory initialization issue.
CVE-2020-3872 affects Apple watchOS versions up to, but not including, 6.1.2.
CVE-2020-3872 affects Apple tvOS versions up to, but not including, 13.3.1.
CVE-2020-3872 affects Apple iOS versions up to, but not including, 13.3.1.
CVE-2020-3872 affects Apple iPadOS versions up to, but not including, 13.3.1.
CVE-2020-3872 affects Apple macOS Catalina versions up to, but not including, 10.15.3.
The impact of CVE-2020-3872 on Apple Mojave is currently unknown.
The impact of CVE-2020-3872 on Apple High Sierra is currently unknown.
To fix CVE-2020-3872, you should update your Apple device to the latest version of watchOS, tvOS, iOS, iPadOS, or macOS Catalina, depending on the affected operating system.
You can find more information about CVE-2020-3872 on the Apple support website.