CVE-2018-20505: Apple iCloud
High severity, CVSS 7.5. EPSS: 7% chance of exploitation in the next 30 days.
SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).
Affected products
- Apple iCloud: before 7.10 (fixed in 7.10)
- Apple iPhone OS: before 12.1.3 (fixed in 12.1.3)
- Apple iTunes: before 12.9.3 (fixed in 12.9.3)
- Apple Mac OS X: before 10.14.2 (fixed in 10.14.2)
- Apple watchOS: before 5.1.3 (fixed in 5.1.3)
- Sqlite Sqlite: up to and including 3.25.2
Published 2019-04-03. Last modified 2026-06-17.