CVE-2020-3891: Apple Ipad OS
Low severity, CVSS 2.4. EPSS: 0.3% chance of exploitation in the next 30 days.
A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4, watchOS 6.2. A person with physical access to a locked iOS device may be able to respond to messages even when replies are disabled.
Affected products
- Apple Ipad OS: before 13.4 (fixed in 13.4)
- Apple iPhone OS: before 13.4 (fixed in 13.4)
- Apple watchOS: before 6.2 (fixed in 6.2)
Published 2020-04-01. Last modified 2026-06-17.