CVE-2026-20637General(apple / ipados)

MEDIUMCVSS 6.2 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for apple ipados systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system termination.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-04-06); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-06: 1Mentions · 2026-04-15: 1Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1PoC Mentioned / Linked · 2026-04-06: 1Exploit Tool / Code · 2026-04-06: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 104-0604-1504-2104-22
Signal classification3 categories
General
250.0%
PoC
125.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-061
PoC1
2026-04-151
General1
2026-04-211
General1
2026-04-221
Disclosure1
Full discourse4 posts
  • zip@zippgod24
    Disclosure

    Rce -> uaf 26.4 down better variant of cve-2026-20637 unpatched https://t.co/jPqzzv78sZ

    Post summary

    The tweet announces a variant of CVE‑2026‑20637 affecting version 26.4 with an RCE-to-UAF flaw, noting it remains unpatched, but provides no PoC, exploit code, or evidence of active exploitation.

    51701635819.2K
    1.8K followersView on X
  • johnny@zeroxjf
    PoC

    For those interested: CVE-2026-20637 — AppleSEPKeyStore UAF https://github.com/zeroxjf/CVE-2026-20637-AppleSEPKeyStore-UAF CVE-2026-20687 — AppleJPEGDriver UAF https://github.com/zeroxjf/CVE-2026-20687-AppleJPEGDriver-UAF

    Post summary

    The post shares GitHub links to proof‑of‑concept code for two Apple use‑after‑free vulnerabilities, providing technical details but no evidence of active exploitation or patches.

    38132173.7K
    4.1K followersView on X
  • zip@zippgod24
    General

    Rce -> uaf 26.4 down better variant of cve-2026-20637 unpatched video tonight

    Post summary

    The tweet references a variant of CVE‑2026‑20637 that involves an RCE escalated to a UAF, but it provides no PoC, exploit code, patch, or evidence of active exploitation; it merely mentions an upcoming unpatched video demonstration.

    0001221.7K
    1.8K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-20637 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-20637 #CVE-2026-20637 #CVE   #CyberSecurity #InfoSec https://t.co/ViG308IEbD

    Post summary

    The tweet announces the existence of CVE‑2026‑20637, gives no technical details, lacks any proof or evidence of exploitation, and directs readers to the NVD entry for more information.

    0000034
    137 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more