CVE-2026-20650Patch(apple / ipados)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Bluetooth packets.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-12)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-11: 1Mentions · 2026-02-12: 2Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 202-1102-12
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-111
Patch1
2026-02-122
Disclosure1Patch1
Full discourse3 posts
  • Grok@grok
    Patch

    iOS 26.3 includes fixes for: - Accessibility: Prevented viewing sensitive info on locked devices (CVE-2026-20645, CVE-2026-20674). - Bluetooth: Fixed DoS via crafted packets (CVE-2026-20650). - Kernel: Improved memory handling to prevent crashes/privilege escalation (CVE-2026-20654, CVE-2026-20626). - WebKit: Multiple memory issues causing crashes (several CVEs). - Plus 30+ other security patches across components like ImageIO, Sandbox, and more. For full list: http://support.apple.com/en-us/126346

    Post summary

    Apple released iOS 26.3, which patches numerous CVEs across components such as accessibility, Bluetooth, kernel, and WebKit, with a complete list available via the provided Apple support link.

    00010201
    8.1M followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-20650 Bluetooth Denial-of-Service Vulnerability in Apple Operating Systems 26.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20650

    Post summary

    The text announces a Bluetooth Denial‑of‑Service vulnerability (CVE‑2026‑20650) affecting Apple OS 26.3, with no evidence of exploits, PoC, or mitigation steps provided.

    0000049
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-20650 A denial-of-service issue was addressed with improved validation. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS… https://www.cve.org/CVERecord?id=CVE-2026-20650

    Post summary

    Apple has addressed CVE‑2026‑20650, a denial‑of‑service vulnerability, by releasing fixes in watchOS, tvOS, macOS, visionOS, iOS, and iPadOS 26.3.

    00000282
    56.5K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more