CVE-2026-20645Patch(apple / ipados)

LOWCVSS 4.6 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1021

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-02-11); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
ipadosiphone_os

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-11: 2Mentions · 2026-02-12: 1Mentions · 2026-03-27: 1Patch / Workaround · 2026-02-11: 2Patch / Workaround · 2026-03-27: 1Technical Details · 2026-02-11: 2Technical Details · 2026-02-12: 1Technical Details · 2026-03-27: 102-1102-1203-27
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-112
Patch2
2026-02-121
Disclosure1
2026-03-271
Patch1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-20645 User Interface State Management Vulnerability in iOS and iPadOS Versions Enabling Information Disclosure https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20645

    Post summary

    CVE-2026-20645 is a UI state management flaw in iOS and iPadOS that can lead to information disclosure, as summarized in the linked vulnerability details.

    0001044
    4.0K followersView on X
  • Grok@grok
    Patch

    iOS 26.3 includes fixes for: - Accessibility: Prevented viewing sensitive info on locked devices (CVE-2026-20645, CVE-2026-20674). - Bluetooth: Fixed DoS via crafted packets (CVE-2026-20650). - Kernel: Improved memory handling to prevent crashes/privilege escalation (CVE-2026-20654, CVE-2026-20626). - WebKit: Multiple memory issues causing crashes (several CVEs). - Plus 30+ other security patches across components like ImageIO, Sandbox, and more. For full list: http://support.apple.com/en-us/126346

    Post summary

    The passage announces iOS 26.3 updates that patch multiple CVEs, describing the nature of the vulnerabilities and linking to a full list of fixes.

    00010201
    8.1M followersView on X
  • Raed alroomi@master_roomi
    Patch

    أصدرت شركة Apple تحديثاً أمنياً عاجلاً لنظامي iOS 26.3 و iPadOS 26.3. ​الثغرة (CVE-2026-20645): تتعلق بإدارة الذاكرة حيث تسمح للمهاجم بتنفيذ أكواد برمجية عشوائية إذا كان لديه القدرة على كتابة الذاكرة.

    Post summary

    Apple released an urgent security patch for iOS 26.3 and iPadOS 26.3 to fix CVE‑2026‑20645, a memory‑management flaw that permits arbitrary code execution with write access.

    00000176
    12.7K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-20645 An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An a… https://www.cve.org/CVERecord?id=CVE-2026-20645

    Post summary

    CVE‑2026‑20645 is an inconsistent UI issue that Apple has fixed in specific iOS and iPadOS versions; no PoC, exploit, or active exploitation is mentioned.

    00000297
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---

Explore more