CVE-2020-3904: High severity apple macOS Catalina vulnerability
AppleGraphicsControl. Multiple memory corruption issues were addressed with improved state management.
Other sources
Multiple memory corruption issues were addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
macOS Catalinato a version that resolves this vulnerability.Fixed in 10.15.4 - Upgrade
Upgrade
AppleGraphicsControlto a version that resolves this vulnerability.Fixed in 10.15.4
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9772
- CVE-2020-3903
- CVE-2020-3904
- CVE-2020-3883
- CVE-2020-6616
- CVE-2020-9853
- CVE-2020-3907
- CVE-2020-3908
- CVE-2020-3912
- CVE-2020-9779
- CVE-2020-3892
- CVE-2020-3893
- CVE-2020-3905
- CVE-2019-8853
- CVE-2020-9776
- CVE-2020-9828
- CVE-2020-3913
- CVE-2020-9829
- CVE-2020-3898
- CVE-2020-3881
- CVE-2020-3886
- CVE-2019-14615
- CVE-2020-3919
- CVE-2020-3851
- CVE-2020-3896
- CVE-2020-3914
- CVE-2020-9785
- CVE-2020-3909
- CVE-2020-3911
- CVE-2020-3910
- CVE-2020-3884
- CVE-2020-3915
- CVE-2020-9775
- CVE-2020-9771
- CVE-2020-3918
- CVE-2019-19232
- CVE-2020-9786
- CVE-2020-3906
- CVE-2020-3889
- CVE-2020-9769
- CVE-2020-9787
- CVE-2020-3902
Frequently Asked Questions
What is CVE-2020-3904?
CVE-2020-3904 is a vulnerability in AppleGraphicsControl that allows for multiple memory corruption issues.
How can macOS Catalina users be affected by CVE-2020-3904?
macOS Catalina version 10.15.4 and earlier are affected by CVE-2020-3904.
Which versions of macOS Mojave are affected by CVE-2020-3904?
All versions of macOS Mojave are affected by CVE-2020-3904.
Are High Sierra users affected by CVE-2020-3904?
Yes, High Sierra is also affected by CVE-2020-3904.
How can I fix CVE-2020-3904?
To fix CVE-2020-3904, update your macOS to version 10.15.5 or later.