First published: Tue Mar 24 2020(Updated: )
An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, watchOS 6.2. Setting an alternate app icon may disclose a photo without needing permission to access photos.
Credit: Vitaliy Alekseev @villy21 Vitaliy Alekseev @villy21 product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple watchOS | <6.2 | 6.2 |
Apple iOS | <13.4 | 13.4 |
Apple iPadOS | <13.4 | 13.4 |
Apple iPadOS | <13.4 | |
Apple iPhone OS | <13.4 | |
Apple watchOS | <6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2020-3916 is a vulnerability that allows for an access issue in the Icons component.
The vulnerability affects Apple iOS versions up to but excluding 13.4.
The vulnerability affects Apple iPadOS versions up to but excluding 13.4.
The vulnerability affects Apple watchOS versions up to but excluding 6.2.
You can find more information on this vulnerability at the following references: [CVE-2020-3916](https://support.apple.com/en-us/HT211103) and [Apple Security Updates](https://support.apple.com/en-us/HT211102).