This issue was addressed with improved setting propagation. This issue is fixed in macOS Big Sur 11.0.1, tvOS 14.0, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, watchOS 7.0, iOS 14.0 and iPadOS 14.0. An attacker in a privileged network position may be able to unexpectedly alter application state.
CVSS v4.0 Metrics
Exploitability
Attack VectorAdjacent
ComplexityLow
RequirementsPresent
PrivilegesHigh
User InteractionNone
Threat
Exploit MaturityUnreported
Vulnerable System
ConfidentialityNone
IntegrityHigh
AvailabilityNone
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-21 | nvd | AV: P→A, AC: H→L, UI: A→N, VI: N→H | 0.0 → 1.9 |
| 2026-07-21 | cve.org | initial, patch: Unavailable | 0.0 |
Affected Software
| Vendor | Product | Version |
|---|
| Apple | iOS and iPadOS | < 14.0 |
| apple | ipados | < 14.0 |
| apple | iphone_os | < 14.0 |
| apple | mac_os_x | ≥ 10.15, < 10.15.7 |
| apple | mac_os_x | ≥ 10.14, < 10.14.6 |
| apple | mac_os_x | 10.14.6 |
| apple | mac_os_x | 10.15.7 |
| Apple | macOS | < 11.0 |
| apple | macos | ≥ 11.0, < 11.1.0 |
| Apple | macOS | < 11.1 |
| Apple | tvOS | < 14.0 |
| apple | watchos | < 7.0 |
| Apple | watchOS | < 7.0 |
Published: 2021-04-02