CVE-2020-3896: Apple Mac OS X

Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Catalina 10.15.4, Security Update 2020-002 Mojave, Security Update 2020-002 High Sierra. A malicious application may be able to overwrite arbitrary files.

Affected products

  • Apple Mac OS X: from 10.13, before 10.13.6 (fixed in 10.13.6); from 10.14, before 10.14.6 (fixed in 10.14.6); from 10.15, before 10.15.4 (fixed in 10.15.4); version 10.13.6 only; version 10.14.6 only

Published 2021-12-23. Last modified 2026-06-17.