CVE-2020-6616: Medium severity macos catalina vulnerability
Bluetooth. An issue existed with the use of a PRNG with low entropy. This issue was addressed with improved state management.
Other sources
Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (PRNG) is used in situations where a Hardware Random Number Generator (HRNG) should have been used to prevent spoofing. This affects, for example, Samsung Galaxy S8, S8+, and Note8 devices with the BCM4361 chipset. The Samsung ID is SVE-2020-16882 (May 2020).
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2020-9772
- CVE-2020-3903
- CVE-2020-3904
- CVE-2020-3883
- CVE-2020-6616
- CVE-2020-9853
- CVE-2020-3907
- CVE-2020-3908
- CVE-2020-3912
- CVE-2020-9779
- CVE-2020-3892
- CVE-2020-3893
- CVE-2020-3905
- CVE-2019-8853
- CVE-2020-9776
- CVE-2020-9828
- CVE-2020-3913
- CVE-2020-9829
- CVE-2020-3898
- CVE-2020-3881
- CVE-2020-3886
- CVE-2019-14615
- CVE-2020-3919
- CVE-2020-3851
- CVE-2020-3896
- CVE-2020-3914
- CVE-2020-9785
- CVE-2020-3909
- CVE-2020-3911
- CVE-2020-3910
- CVE-2020-3884
- CVE-2020-3915
- CVE-2020-9775
- CVE-2020-9771
- CVE-2020-3918
- CVE-2019-19232
- CVE-2020-9786
- CVE-2020-3906
- CVE-2020-3889
- CVE-2020-9769
- CVE-2020-9787
- CVE-2020-3902
- CVE-2020-9827
- CVE-2020-9826
- CVE-2020-9842
- CVE-2020-9815
- CVE-2020-9791
- CVE-2020-9838
- CVE-2020-9835
- CVE-2020-9820
- CVE-2020-9816
- CVE-2020-3878
- CVE-2020-9789
- CVE-2020-9790
- CVE-2020-9837
- CVE-2020-9821
- CVE-2020-9797
- CVE-2020-9852
- CVE-2020-9795
- CVE-2020-9808
- CVE-2020-9811
- CVE-2020-9812
- CVE-2020-9813
- CVE-2020-9814
- CVE-2020-9809
- CVE-2020-9994
- CVE-2020-9819
- CVE-2020-9818
- CVE-2020-9823
- CVE-2020-9848
- CVE-2014-9512
- CVE-2020-9825
- CVE-2020-9854
- CVE-2020-9794
- CVE-2020-9839
- CVE-2020-9792
- CVE-2020-9805
- CVE-2020-9802
- CVE-2020-9850
- CVE-2020-9843
- CVE-2020-9803
- CVE-2020-9806
- CVE-2020-9807
- CVE-2020-9800
- CVE-2019-20503
- CVE-2020-9844
- CVE-2020-9830
Frequently Asked Questions
What is CVE-2020-6616?
CVE-2020-6616 is a vulnerability related to the use of a PRNG with low entropy in Bluetooth.
What is the severity of CVE-2020-6616?
The severity of CVE-2020-6616 has not been provided.
How does CVE-2020-6616 affect Apple macOS Catalina?
CVE-2020-6616 affects Apple macOS Catalina version up to 10.15.4.
How does CVE-2020-6616 affect Apple iOS?
CVE-2020-6616 affects Apple iOS version up to 13.5.
How can I fix CVE-2020-6616?
To fix CVE-2020-6616, update your operating system to the recommended version provided by Apple.