CVE-2020-3886: Apple Mac OS X

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra. A malicious application may be able to execute arbitrary code with kernel privileges.

Affected products

  • Apple Mac OS X: from 10.13, before 10.13.6 (fixed in 10.13.6); from 10.14, before 10.14.6 (fixed in 10.14.6); from 10.15, before 10.15.4 (fixed in 10.15.4); version 10.13.6 only; version 10.14.6 only

Published 2021-12-23. Last modified 2026-06-17.