CVE-2020-3848 is a critical memory corruption vulnerability affecting Apple macOS Catalina 10.15.2 and earlier, addressed in version 10.15.3. This flaw, stemming from insufficient input validation, allows a remote attacker to cause application termination or execute arbitrary code. With a CVSS score of 9.8 (CRITICAL), it presents a significant risk due to its network-based attack vector and low complexity, potentially leading to full compromise of confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or Nuclei templates are currently available, and community discussion is minimal, the high CVSS score and FAUCET Risk Score of 80/100 indicate its severe potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.15.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.