CVE-2026-20653Disclosure(apple / ipados)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • visionos

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-11); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacosvisionos

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-11: 2Mentions · 2026-02-12: 1Patch / Workaround · 2026-02-11: 1Technical Details · 2026-02-11: 2Technical Details · 2026-02-12: 102-1102-12
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-112
Disclosure1Patch1
2026-02-121
Disclosure1
Full discourse3 posts
  • Enis@enismaholli
    Disclosure

    CVE-2026-20653  I reported a parsing vulnerability affecting the latest versions of macOS and iOS that could allow an app to access and exfiltrate sensitive data, including your camera feed and data protected by TCC. Technical details coming soon on http://enismaholli.com https://t.co/HdPhyXPCYK

    Post summary

    A new parsing vulnerability (CVE-2026-20653) affecting macOS and iOS could allow apps to exfiltrate sensitive data such as camera feeds and TCC‑protected information. Technical details are slated to be released soon.

    23054122.8K
    42 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-20653 Path Traversal Vulnerability in Apple Operating Systems Allows Un... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20653 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The text announces CVE‑2026‑20653, a path‑traversal flaw in Apple OS, and provides a link for further details.

    0001043
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-20653 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Se… https://www.cve.org/CVERecord?id=CVE-2026-20653

    Post summary

    The post announces a directory‑path parsing vulnerability (CVE‑2026‑20653) that is mitigated in specific macOS releases, highlighting the vendor’s patch.

    00000173
    56.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSapplevisionos---

Explore more