CVE-2020-3891: Apple Ipad OS

Low severity, CVSS 2.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A logic issue was addressed with improved state management. This issue is fixed in iOS 13.4 and iPadOS 13.4, watchOS 6.2. A person with physical access to a locked iOS device may be able to respond to messages even when replies are disabled.

Affected products

  • Apple Ipad OS: before 13.4 (fixed in 13.4)
  • Apple iPhone OS: before 13.4 (fixed in 13.4)
  • Apple watchOS: before 6.2 (fixed in 6.2)

Published 2020-04-01. Last modified 2026-06-17.