CVE-2020-27902: Apple iPadOS

Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.

An authentication issue was addressed with improved state management. This issue is fixed in iOS 14.2 and iPadOS 14.2. A person with physical access to an iOS device may be able to access stored passwords without authentication.

Affected products

  • Apple iPadOS: before 14.2 (fixed in 14.2)
  • Apple iPhone OS: before 14.2 (fixed in 14.2)

Published 2020-12-08. Last modified 2026-06-17.