CVE-2026-20642Disclosure(apple / ipados)

LOWCVSS 2.4 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person with physical access to an iOS device may be able to access photos from the lock screen.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-12)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_os

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-11: 1Mentions · 2026-02-12: 3Patch / Workaround · 2026-02-12: 2Technical Details · 2026-02-12: 302-1102-12
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-111
Disclosure1
2026-02-123
Disclosure1Patch2
Full discourse4 posts
  • Dali@lipskamafia
    Disclosure

    Apple paid me $1,000 for CVE-2026-20642. Thanks for the bounty! #bugbounty #securityresearch #infosec #hacker #CVE #apple #ios #togetherwehitharder #applebounty https://t.co/ACl2kn165A

    Post summary

    The researcher announces a $1,000 bounty from Apple for CVE‑2026‑20642, confirming the vulnerability’s disclosure but offering no technical exploitation details.

    10030283
    155 followersView on X
  • Hespress English@HespressEnglish
    Patch

    Apple’s February 11, 2026 security updates include a fix for a Photos vulnerability that could let someone with physical access to a locked iPhone or iPad view photos from the lock screen. Apple says the issue (CVE-2026-20642, credited to Dalibor Milanovic) was caused by an input validation flaw and is addressed in iOS 26.3 and iPadOS 26.3 for iPhone 11 and later and several recent iPad models. In a separate patch, Apple fixed a Safari logic issue that could allow an app to access a user’s Safari browsing history. The flaw (CVE-2026-20656, credited to Mickey Jin) was resolved with improved validation and is listed in iOS 18.7.5/iPadOS 18.7.5 for iPhone XS/XS Max/XR and iPad (7th gen), as well as Safari 26.3 on macOS Sonoma and macOS Sequoia. Users are advised to update promptly to reduce privacy risk.

    Post summary

    Apple released updates for CVE‑2026‑20642 and CVE‑2026‑20656, fixing input validation flaws that could let attackers view locked‑screen photos or access browsing history, and urges users to install iOS 26.3, iPadOS 26.3, or iOS 18.7.5/Safari 26.3 promptly.

    00000146
    2.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-20642 iOS Lock Screen Photo Access Vulnerability in Versions Prior to 26.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20642

    Post summary

    The text announces CVE-2026-20642, detailing a lock‑screen photo access flaw in iOS versions before 26.3, with no information on PoC, exploitation, patches, or active use.

    0000084
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-20642 An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person with physical access to an iOS device may be able to access photos … https://www.cve.org/CVERecord?id=CVE-2026-20642

    Post summary

    The text announces that CVE‑2026‑20642, an input‑validation flaw permitting physical access to photos, has been fixed in iOS 26.3 and iPadOS 26.3.

    00000147
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---

Explore more