CVE-2020-3844
LOWiPadOS < 13.3.1 - Unauthenticated iMessage State Manipulation
Title source: llmDescription
This issue was addressed with improved checks. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Users removed from an iMessage conversation may still be able to alter state.
References (1)
Core 1
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://support.apple.com/HT210918
Scores
CVSS v3
3.3
EPSS
0.0028
EPSS Percentile
20.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Details
Status
published
Products (2)
apple/ipados
< 13.3.1
apple/iphone_os
< 13.3.1
Published
Feb 27, 2020
Tracked Since
Feb 18, 2026