Vulnerability Intelligence Report
CVE-2020-3843
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4.7, watchOS 5.3.7. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.
No Active Exploit Signals
CVSS Base Score
8.8
HIGH
EPSS Probability:3.48%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Apple | iOS-1 | unspecified < iOS 12.4.7 (affected) |
| Apple | watchOS-1 | unspecified < watchOS 5.3.7 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
3.475%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Apple Inc. · Vendor · USA |
| Reserved | 2019-12-18T00:00:00 |
| Published | 2020-02-27T20:45:04 |
| Last Updated | 2024-08-04T07:44:51 |
Community Chatter & Buzz