CVE-2018-20505: Apple iCloud

High severity, CVSS 7.5. EPSS: 7% chance of exploitation in the next 30 days.

SQLite 3.25.2, when queries are run on a table with a malformed PRIMARY KEY, allows remote attackers to cause a denial of service (application crash) by leveraging the ability to run arbitrary SQL statements (such as in certain WebSQL use cases).

Affected products

  • Apple iCloud: before 7.10 (fixed in 7.10)
  • Apple iPhone OS: before 12.1.3 (fixed in 12.1.3)
  • Apple iTunes: before 12.9.3 (fixed in 12.9.3)
  • Apple Mac OS X: before 10.14.2 (fixed in 10.14.2)
  • Apple watchOS: before 5.1.3 (fixed in 5.1.3)
  • Sqlite Sqlite: up to and including 3.25.2

Published 2019-04-03. Last modified 2026-06-17.