CVE-2020-3837 is a memory corruption vulnerability, specifically an out-of-bounds write, affecting Apple's iOS, iPadOS, macOS, tvOS, and watchOS. This flaw allows an application to execute arbitrary code with kernel privileges. With a CVSS score of 7.8 (High) and a FAUCET Risk Score of 99/100, it presents a significant risk, requiring user interaction (UI:R) for exploitation but offering full confidentiality, integrity, and availability impact (C:H/I:H/A:H). The vulnerability has been actively exploited in the wild, as indicated by its presence in the KEV catalog, and exploit code (EDB-48035) is publicly available. It has garnered substantial community discussion and media coverage, including reports of spyware leveraging similar vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 13.3.1CPE matchmatch criteria | cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:* | ||
< 13.3.1CPE matchmatch criteria | cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:* | ||
< 10.15.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 13.3.1CPE matchmatch criteria | cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:* | ||
< 6.1.2CPE matchmatch criteria | cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.