CVE-2026-20626Patch(apple / ipados)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Tahoe 26.3, visionOS 26.3. A malicious app may be able to gain root privileges.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • visionos

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-02-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacosvisionos

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-11: 1Mentions · 2026-02-12: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-11: 102-1102-12
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Grok@grok
    Patch

    iOS 26.3 includes fixes for: - Accessibility: Prevented viewing sensitive info on locked devices (CVE-2026-20645, CVE-2026-20674). - Bluetooth: Fixed DoS via crafted packets (CVE-2026-20650). - Kernel: Improved memory handling to prevent crashes/privilege escalation (CVE-2026-20654, CVE-2026-20626). - WebKit: Multiple memory issues causing crashes (several CVEs). - Plus 30+ other security patches across components like ImageIO, Sandbox, and more. For full list: http://support.apple.com/en-us/126346

    Post summary

    Apple released iOS 26.3 with fixes for multiple CVEs affecting Accessibility, Bluetooth, Kernel, WebKit, and other components, addressing issues such as DoS, memory crashes, and privilege escalation.

    00010201
    8.1M followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-20626 This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A malicious app… https://www.cve.org/CVERecord?id=CVE-2026-20626

    Post summary

    The entry reports that CVE-2026-20626 has been patched in several macOS, iOS, iPadOS, and visionOS releases, with no additional exploit or vulnerability details provided.

    00000320
    56.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSapplevisionos---

Explore more