CVE-2020-3844: Apple iPadOS

Low severity, CVSS 3.3. EPSS: 0.3% chance of exploitation in the next 30 days.

This issue was addressed with improved checks. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Users removed from an iMessage conversation may still be able to alter state.

Affected products

  • Apple iPadOS: before 13.3.1 (fixed in 13.3.1)
  • Apple iPhone OS: before 13.3.1 (fixed in 13.3.1)

Published 2020-02-27. Last modified 2026-06-17.