VulnerabilityModified
CVE-2020-3916
Setting an alternate app icon may disclose a photo without needing permission to access photos.
MEDIUM 5.3EPSS 0.81%
Does this matter?
Lower severity and a low EPSS score (0.81%). Track it; it rarely justifies an emergency change on its own.
Description
An access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 13.4 and iPadOS 13.4, watchOS 6.2. Setting an alternate app icon may disclose a photo without needing permission to access photos.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.81% probability · 55th percentile
- CISA KEV
- Not listed
- Affected
- apple/ipados · apple/iphone os · apple/watchos
- Source
- product-security@apple.com
References
- https://support.apple.com/HT211102Vendor Advisory
- https://support.apple.com/HT211103Vendor Advisory
- https://support.apple.com/HT211102Vendor Advisory
- https://support.apple.com/HT211103Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.