Apple Security Advisories · March 2020 — Apple Security Advisories
48 advisories 48 CVEs

Apple-vendor CVEs for 2020-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2020-3894

iPadOSWeaponized exploitLOW2020-03-25

A race condition was addressed with additional validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. An application may be able to read restr...

CVEs:CVE-2020-3894

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipad_os affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2020-10663

OtherPoC exploitHIGH2020-03-20

The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior...

CVEs:CVE-2020-10663

Affected products

ProductStatusVendorPackageEcosystem
macos affected apple
Upstream advisory

CVE-2020-3897

iPadOSEPSS <= 49%HIGH2020-03-25

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A remote attacker ...

CVEs:CVE-2020-3897

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipad_os affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-3899

iPadOSEPSS <= 49%HIGH2020-03-25

A memory consumption issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A remote attac...

CVEs:CVE-2020-3899

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipad_os affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-3909

iPadOSEPSS <= 49%CRITICAL2020-03-25

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple iss...

CVEs:CVE-2020-3909

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-3895

iPadOSEPSS <= 49%HIGH2020-03-25

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing mali...

CVEs:CVE-2020-3895

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipad_os affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-3900

iPadOSEPSS <= 49%CRITICAL2020-03-25

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing mali...

CVEs:CVE-2020-3900

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipad_os affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-3901

iPadOSEPSS <= 49%CRITICAL2020-03-25

A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing malicio...

CVEs:CVE-2020-3901

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipad_os affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-3885

iPadOSEPSS <= 49%MEDIUM2020-03-25

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A file URL may be incorrectly processed.

CVEs:CVE-2020-3885

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipad_os affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2020-3911

iPadOSEPSS <= 49%CRITICAL2020-03-25

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple iss...

CVEs:CVE-2020-3911

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-3910

iPadOSEPSS <= 49%CRITICAL2020-03-25

A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Multiple iss...

CVEs:CVE-2020-3910

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-3919

iPadOSEPSS <= 49%HIGH2020-03-25

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A malicious application may be able to execute arbitrary code with kernel privil...

CVEs:CVE-2020-3919

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-3892

macOSEPSS <= 49%HIGH2020-03-25

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-3892

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-3893

macOSEPSS <= 49%HIGH2020-03-25

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-3893

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-3905

macOSEPSS <= 49%HIGH2020-03-25

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-3905

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-3903

macOSEPSS <= 49%HIGH2020-03-25

A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.4. An application may be able to execute arbitrary code with system privileges.

CVEs:CVE-2020-3903

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-3904

macOSEPSS <= 49%HIGH2020-03-25

Multiple memory corruption issues were addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-3904

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-9795

iPadOSEPSS <= 49%HIGH2020-03-27

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. An application may be able to execute arbitrary code with kernel privileges.

CVEs:CVE-2020-9795

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9783

iPadOSEPSS <= 49%CRITICAL2020-03-25

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously crafte...

CVEs:CVE-2020-9783

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipados affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2020-9785

iPadOSEPSS <= 49%HIGH2020-03-25

Multiple memory corruption issues were addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. A malicious application may be able to execute arbitrary code with kernel ...

CVEs:CVE-2020-9785

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9768

iPadOSEPSS <= 49%HIGH2020-03-25

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2. An application may be able to execute arbitrary code with system privileges.

CVEs:CVE-2020-9768

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9770

iPadOSEPSS <= 49%HIGH2020-03-25

A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4. An attacker in a privileged network position may be able to intercept Bluetooth traffic.

CVEs:CVE-2020-9770

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2020-3887

iPadOSEPSS <= 49%MEDIUM2020-03-25

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. A download's origin may be incorrectly asso...

CVEs:CVE-2020-3887

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipad_os affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2020-3902

iPadOSEPSS <= 49%CRITICAL2020-03-25

An input validation issue was addressed with improved input validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, Safari 13.1, iTunes for Windows 12.10.5, iCloud for Windows 10.9.3, iCloud for Windows 7.18. Processing maliciously craf...

CVEs:CVE-2020-3902

Affected products

ProductStatusVendorPackageEcosystem
icloud affected apple
ipad_os affected apple
iphone_os affected apple
itunes affected apple
safari affected apple
tvos affected apple
Upstream advisory

CVE-2020-3884

macOSEPSS <= 49%CRITICAL2020-03-25

An injection issue was addressed with improved validation. This issue is fixed in macOS Catalina 10.15.4. A remote attacker may be able to cause arbitrary javascript code execution.

CVEs:CVE-2020-3884

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-9769

macOSEPSS <= 49%CRITICAL2020-03-25

Multiple issues were addressed by updating to version 8.1.1850. This issue is fixed in macOS Catalina 10.15.4. Multiple issues in Vim.

CVEs:CVE-2020-9769

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-3883

iPadOSEPSS <= 49%HIGH2020-03-25

This issue was addressed with improved checks. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. An application may be able to use arbitrary entitlements.

CVEs:CVE-2020-3883

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-3906

macOSEPSS <= 49%CRITICAL2020-03-25

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.4. A maliciously crafted application may be able to bypass code signing enforcement.

CVEs:CVE-2020-3906

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-9775

iPadOSEPSS <= 49%MEDIUM2020-03-25

An issue existed in the handling of tabs displaying picture in picture video. The issue was corrected with improved state handling. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user's private browsing activity may be unexpectedly saved in Screen ...

CVEs:CVE-2020-9775

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
Upstream advisory

CVE-2020-9784

SafariEPSS <= 49%MEDIUM2020-03-25

A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1. A malicious iframe may use another website’s download settings.

CVEs:CVE-2020-9784

Affected products

ProductStatusVendorPackageEcosystem
safari affected apple
Upstream advisory

CVE-2020-3916

iPadOSEPSS <= 49%MEDIUM2020-03-25

An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, watchOS 6.2. Setting an alternate app icon may disclose a photo without needing permission to access photos.

CVEs:CVE-2020-3916

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
watchos affected apple
Upstream advisory

CVE-2020-3890

iPadOSEPSS <= 49%MEDIUM2020-03-25

The issue was addressed with improved deletion. This issue is fixed in iOS 13.4 and iPadOS 13.4. Deleted messages groups may still be suggested as an autocompletion.

CVEs:CVE-2020-3890

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
Upstream advisory

CVE-2020-9777

iPadOSEPSS <= 49%MEDIUM2020-03-25

An issue existed in the selection of video file by Mail. The issue was fixed by selecting the latest version of a video. This issue is fixed in iOS 13.4 and iPadOS 13.4. Cropped videos may not be shared properly via Mail.

CVEs:CVE-2020-9777

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2020-3851

macOSEPSS <= 49%CRITICAL2020-03-25

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra, macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Securit...

CVEs:CVE-2020-3851

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-3914

iPadOSEPSS <= 49%MEDIUM2020-03-25

A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, tvOS 13.4, watchOS 6.2. An application may be able to read restricted memory.

CVEs:CVE-2020-3914

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-9781

iPadOSEPSS <= 49%MEDIUM2020-03-25

The issue was addressed by clearing website permission prompts after navigation. This issue is fixed in iOS 13.4 and iPadOS 13.4. A user may grant website permissions to a site they didn't intend to.

CVEs:CVE-2020-9781

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2020-3913

iPadOSEPSS <= 49%HIGH2020-03-25

A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, watchOS 6.2. A malicious application may be able to elevate privileges.

CVEs:CVE-2020-3913

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
mac_os_x affected apple
watchos affected apple
Upstream advisory

CVE-2020-3888

iPadOSEPSS <= 49%MEDIUM2020-03-25

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4. A maliciously crafted page may interfere with other web contexts.

CVEs:CVE-2020-3888

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
Upstream advisory

CVE-2020-9773

iPadOSEPSS <= 49%MEDIUM2020-03-25

The issue was addressed with improved handling of icon caches. This issue is fixed in iOS 14.0 and iPadOS 14.0. A malicious application may be able to identify what other applications a user has installed.

CVEs:CVE-2020-9773

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

CVE-2020-9776

macOSEPSS <= 49%MEDIUM2020-03-25

This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to access a user's call history.

CVEs:CVE-2020-9776

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-3907

macOSEPSS <= 49%HIGH2020-03-25

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.

CVEs:CVE-2020-3907

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-3881

macOSEPSS <= 49%MEDIUM2020-03-25

A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to view sensitive user information.

CVEs:CVE-2020-3881

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-3889

macOSEPSS <= 49%MEDIUM2020-03-25

A logic issue was addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to read arbitrary files.

CVEs:CVE-2020-3889

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-3912

macOSEPSS <= 49%HIGH2020-03-25

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.

CVEs:CVE-2020-3912

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-3908

macOSEPSS <= 49%HIGH2020-03-25

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.4. A local user may be able to cause unexpected system termination or read kernel memory.

CVEs:CVE-2020-3908

Affected products

ProductStatusVendorPackageEcosystem
mac_os_x affected apple
Upstream advisory

CVE-2020-3917

iPadOSEPSS <= 49%MEDIUM2020-03-25

This issue was addressed with a new entitlement. This issue is fixed in iOS 13.4 and iPadOS 13.4, tvOS 13.4, watchOS 6.2. An application may be able to use an SSH client provided by private frameworks.

CVEs:CVE-2020-3917

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
tvos affected apple
watchos affected apple
Upstream advisory

CVE-2020-3891

iPadOSEPSS <= 49%LOW2020-03-25

A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4, watchOS 6.2. A person with physical access to a locked iOS device may be able to respond to messages even when replies are disabled.

CVEs:CVE-2020-3891

Affected products

ProductStatusVendorPackageEcosystem
ipad_os affected apple
iphone_os affected apple
watchos affected apple
Upstream advisory

CVE-2020-9780

iPadOSEPSS <= 49%LOW2020-03-25

The issue was resolved by clearing application previews when content is deleted. This issue is fixed in iOS 13.4 and iPadOS 13.4. A local user may be able to view deleted content in the app switcher.

CVEs:CVE-2020-9780

Affected products

ProductStatusVendorPackageEcosystem
ipados affected apple
iphone_os affected apple
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.