CVE-2020-3913: High severity Apple macOS Catalina vulnerability
CoreFoundation. A permissions issue existed. This issue was addressed with improved permission validation.
Other sources
A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in iOS 13.4 and iPadOS 13.4, macOS Catalina 10.15.4, watchOS 6.2. A malicious application may be able to elevate privileges.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
macOS Catalinato a version that resolves this vulnerability.Fixed in 10.15.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and watchOSto a version that resolves this vulnerability.Fixed in 6.2 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 13.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iOS 13.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in iPadOS 13.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in macOS Catalina 10.15.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in watchOS 6.2 - Configuration
Update to the versions where CoreFoundation has improved permission validation to resolve the permissions issue that enabled possible privilege elevation.
CoreFoundation permission validation = improved
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9772
- CVE-2020-3903
- CVE-2020-3904
- CVE-2020-3883
- CVE-2020-6616
- CVE-2020-9853
- CVE-2020-3907
- CVE-2020-3908
- CVE-2020-3912
- CVE-2020-9779
- CVE-2020-3892
- CVE-2020-3893
- CVE-2020-3905
- CVE-2019-8853
- CVE-2020-9776
- CVE-2020-9828
- CVE-2020-3913
- CVE-2020-9829
- CVE-2020-3898
- CVE-2020-3881
- CVE-2020-3886
- CVE-2019-14615
- CVE-2020-3919
- CVE-2020-3851
- CVE-2020-3896
- CVE-2020-3914
- CVE-2020-9785
- CVE-2020-3909
- CVE-2020-3911
- CVE-2020-3910
- CVE-2020-3884
- CVE-2020-3915
- CVE-2020-9775
- CVE-2020-9771
- CVE-2020-3918
- CVE-2019-19232
- CVE-2020-9786
- CVE-2020-3906
- CVE-2020-3889
- CVE-2020-9769
- CVE-2020-9787
- CVE-2020-3902
- CVE-2020-3917
- CVE-2020-3916
- CVE-2020-9768
- CVE-2020-3891
- CVE-2020-3899
- CVE-2020-3895
- CVE-2020-3900
- CVE-2020-3901
- CVE-2020-3897
- CVE-2020-9770
- CVE-2020-9780
- CVE-2020-9777
- CVE-2020-3890
- CVE-2020-9781
- CVE-2020-3888
- CVE-2020-3894
- CVE-2020-3887
- CVE-2020-9783
- CVE-2020-3885
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-3913.
What is the affected software?
The affected software includes macOS Catalina (10.15.4), Apple Mojave, Apple High Sierra, Apple iOS (up to version 13.4), Apple iPadOS (up to version 13.4), and Apple watchOS (up to version 6.2).
What is the severity of CVE-2020-3913?
The severity of CVE-2020-3913 is not specified in the provided information.
How was this vulnerability addressed?
This vulnerability was addressed with improved permission validation.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the following Apple support pages: [link 1](https://support.apple.com/en-us/HT211103), [link 2](https://support.apple.com/en-us/HT211100), [link 3](https://support.apple.com/en-us/HT211102).