CVE-2020-3906: Apple Mac OS X

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.4. A maliciously crafted application may be able to bypass code signing enforcement.

Affected products

  • Apple Mac OS X: before 10.15.4 (fixed in 10.15.4)

Published 2020-04-01. Last modified 2026-06-17.