CVE-2020-27895: Apple iTunes
Low severity, CVSS 3.3. EPSS: 0.7% chance of exploitation in the next 30 days.
An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling. This issue is fixed in iTunes 12.11 for Windows. A malicious application may be able to access local users Apple IDs.
Affected products
- Apple iTunes: before 12.11 (fixed in 12.11)
Published 2020-12-08. Last modified 2026-06-17.