CVE-2020-3916Sensitive Information Exposure in Apple Watchos

Severity
5.3MEDIUMNVD
EPSS
0.2%
top 56.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1
Latest updateMay 24

Description

An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, watchOS 6.2. Setting an alternate app icon may disclose a photo without needing permission to access photos.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

NVDapple/ipados< 13.4
CVEListV5apple/watchosunspecifiedwatchOS 6.2
NVDapple/watchos< 6.2
CVEListV5apple/iosunspecifiediOS 13.4 and iPadOS 13.4
NVDapple/iphone_os< 13.4

🔴Vulnerability Details

2
GHSA
GHSA-3q67-g228-h5qx: An access issue was addressed with additional sandbox restrictions2022-05-24
CVEList
CVE-2020-3916: An access issue was addressed with additional sandbox restrictions2020-04-01
CVE-2020-3916 — Sensitive Information Exposure in Apple | cvebase