CVE-2026-20633Patch(apple / macos)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple macos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to access user-sensitive data.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-25); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
macos

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-25: 1Mentions · 2026-04-15: 1Mentions · 2026-05-20: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-03-25: 103-2504-1505-20
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-251
Patch1
2026-04-151
General1
2026-05-201
Patch1
Full discourse3 posts
  • Mickey Jin@patch1t
    Patch

    @mysk_co This one is similar to my CVE-2026-20633, patched in macOS 26.4 too. However, my bug doesn’t require any user interaction. I can’t disclose the details right now because I have already submitted a bypass report 🫣

    Post summary

    The author confirms a CVE similar to a previous one, noting it is patched in macOS 26.4 and requires no user interaction, but withholds further technical details pending a submitted bypass report.

    100921.4K
    5.3K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-20633 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-20633 #CVE-2026-20633 #CVE   #CyberSecurity #InfoSec https://t.co/pVDJTvHJDi

    Post summary

    The tweet merely announces a new CVE with no additional details beyond a link to the NVD entry.

    0000028
    137 followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 MacOS users: A recent vulnerability in how symlinks are handled could expose sensitive data. Upgrade to Sequoia 15.7.5, Sonoma 14.8.5, or Tahoe 26.4 ASAP to protect yourself! 🔒 Stay secure and share your updates! #MacOS #CyberSecurity Read more: https://www.tenable.com/cve/CVE-2026-20633

    Post summary

    A new vulnerability affecting symlink handling on macOS could expose sensitive data; users are advised to update to the latest OS releases (Sequoia 15.7.5, Sonoma 14.8.5, Tahoe 26.4) to mitigate the issue.

    0000080
    257 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---

Explore more