CVE-2026-20614Patch(apple / macos)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple macos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to gain root privileges.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-12); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
macos

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-12: 2Mentions · 2026-03-17: 1Patch / Workaround · 2026-02-12: 2Technical Details · 2026-02-12: 202-1203-17
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-122
Patch2
2026-03-171
General1
Full discourse3 posts
  • mRr3b00t@UK_Daniel_Card
    General

    I wonder if this actually works? CVE-2026-20614 https://t.co/F2nBkEwovw

    Post summary

    The tweet merely references CVE-2026-20614 and provides a URL, without any additional details about the vulnerability, PoC, exploitation, or patch.

    110221.1K
    120.5K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-20614 A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3, macOS Sonoma 14.8.4. An app may be able t… https://www.cve.org/CVERecord?id=CVE-2026-20614

    Post summary

    CVE‑2026‑20614 is a path handling vulnerability that has been patched in macOS Sequoia 15.7.4, macOS Tahoe 26.3, and macOS Sonoma 14.8.4.

    00000181
    56.5K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL macOS flaw! CVE-2026-20614 lets malicious apps gain root privileges without user interaction. Patch Sequoia 15.7.4, Tahoe 26.3, Sonoma 14.8.4 ASAP. European orgs especially at risk. https://radar.offseq.com/threat/cve-2026-20614-an-app-may-be-able-to-gain-root-pri-3... https://t.co/nLV0oDcsy7

    Post summary

    The tweet announces a critical macOS privilege‑escalation flaw (CVE‑2026‑20614) and provides specific patch versions, but offers no PoC or exploitation details.

    00000129
    268 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---

Explore more