Skip to content
appaloosa scout logo main rounded
LOW 3.3

CVE-2020-27895

An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling. This issue is fixed in iTunes 12.11 for Windows. A malicious application may be able to access local users Apple IDs.

CVSS v3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS 0.2% percentile 37.7%

Affected tracked apps

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
apple itunes Windows <12.11 cpe:2.3:a:apple:itunes:*:*:*:*:*:windows:*:*
View on NVD ↗