CVE-2020-3916
MEDIUMiPadOS < 13.4 - Unprotected Photo Data Exposure via Alternate App Icon
Title source: llmDescription
An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, watchOS 6.2. Setting an alternate app icon may disclose a photo without needing permission to access photos.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://support.apple.com/HT211102
Vendor Advisory x_refsource_misc
https://support.apple.com/HT211103
Scores
CVSS v3
5.3
EPSS
0.0081
EPSS Percentile
52.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Details
Status
published
Products (3)
apple/ipados
< 13.4
apple/iphone_os
< 13.4
apple/watchos
< 6.2
Published
Apr 01, 2020
Tracked Since
Feb 18, 2026