CVE-2020-3855 is an access issue in macOS that allows a malicious application to overwrite arbitrary files due to insufficient access restrictions. This vulnerability affects macOS Catalina, Mojave, and High Sierra, and has been patched in macOS Catalina 10.15.3 and Security Updates 2020-001 for Mojave and High Sierra. With a CVSS score of 7.1 (HIGH), it has a local attack vector, low attack complexity, and can lead to high integrity and availability impacts. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.15.3CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
< 10.15CPE match | cpe:2.3:a:apple:macos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.