CVE-2020-3866: Apple Mac OS X

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

This was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Catalina 10.15.3. Searching for and opening a file from an attacker controlled NFS mount may bypass Gatekeeper.

Affected products

  • Apple Mac OS X: before 10.15.3 (fixed in 10.15.3)

Published 2020-02-27. Last modified 2026-06-17.