CVE-2020-3916

MEDIUM

iPadOS < 13.4 - Unprotected Photo Data Exposure via Alternate App Icon

Title source: llm
STIX 2.1

Description

An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, watchOS 6.2. Setting an alternate app icon may disclose a photo without needing permission to access photos.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/HT211102
Vendor Advisory x_refsource_misc
https://support.apple.com/HT211103

Scores

CVSS v3 5.3
EPSS 0.0081
EPSS Percentile 52.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

Status published
Products (3)
apple/ipados < 13.4
apple/iphone_os < 13.4
apple/watchos < 6.2
Published Apr 01, 2020
Tracked Since Feb 18, 2026