CVE-2020-3882: Apple Mac OS X
Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. Importing a maliciously crafted calendar invitation may exfiltrate user information.
Affected products
- Apple Mac OS X: before 10.15.5 (fixed in 10.15.5)
Published 2020-06-09. Last modified 2026-06-17.