CVE-2026-20654General(apple / ipados)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system termination.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • General: 4 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-02-12); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-02-11: 1Mentions · 2026-02-12: 3Mentions · 2026-02-13: 1Mentions · 2026-04-01: 1Mentions · 2026-07-26: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-11: 102-1102-1202-1304-0107-26
Signal classification3 categories
General
457.1%
Patch
228.6%
Disclosure
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-111
Patch1
2026-02-123
General2Patch1
2026-02-131
General1
2026-04-011
General1
2026-07-261
Disclosure1
Full discourse7 posts
  • Speedyfriend67@speedyfriend433
    General

    Got my first Apple CVE! CVE-2026-20654 At the age of 19, I have finally achieved my goal. Weird thing is, the 2025 CVE isn't addressed yet haha More exciting news coming soon! Thank you everyone for the support 🥹🙏 https://t.co/L5OjKrQ8wB

    Post summary

    The user announces that they have discovered an Apple CVE but provides no technical details, exploit code, or evidence of active exploitation.

    161022692517.1K
    2.4K followersView on X
  • Silzee@SilzeeJailbreak
    General

    Apple CVE! CVE-2026-20654 By @speedyfriend433 https://t.co/L8sXmS8H08

    Post summary

    The tweet simply announces the existence of Apple CVE-2026-20654 without any additional context or detail.

    2404636.2K
    31.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-20654 Kernel Memory Handling Vulnerability in Apple Operating Systems 26.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20654

    Post summary

    The content merely lists the CVE and links to a database entry, providing no additional technical or exploitation information.

    00030102
    4.0K followersView on X
  • Speedyfriend67@speedyfriend433
    Disclosure

    @alencristen I just gave them my 3 Apple CVEs (CVE-2025-46280, CVE-2026-20654, CVE-2026-28867) and my GitHub profile for responsible disclosures

    Post summary

    The user reports three Apple CVEs via a responsible disclosure, offering no proof of concept, exploit code, or technical details.

    10010133
    2.6K followersView on X
  • Speedyfriend67@speedyfriend433
    General

    @t15_v Correct 👍 Was trying to reproduce my previous CVE-2026-20654 with different ways I guess this also relates to the memory handling issue

    Post summary

    The tweet reflects an attempt to reproduce a previously disclosed CVE, but it offers no new technical details or actionable intelligence.

    00010271
    2.5K followersView on X
  • Grok@grok
    Patch

    iOS 26.3 includes fixes for: - Accessibility: Prevented viewing sensitive info on locked devices (CVE-2026-20645, CVE-2026-20674). - Bluetooth: Fixed DoS via crafted packets (CVE-2026-20650). - Kernel: Improved memory handling to prevent crashes/privilege escalation (CVE-2026-20654, CVE-2026-20626). - WebKit: Multiple memory issues causing crashes (several CVEs). - Plus 30+ other security patches across components like ImageIO, Sandbox, and more. For full list: http://support.apple.com/en-us/126346

    Post summary

    Apple’s iOS 26.3 release includes patches for multiple CVEs across several components, addressing issues such as DoS, memory handling, and privilege escalation.

    00010201
    8.1M followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-20654 The issue was addressed with improved memory handling. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An a… https://www.cve.org/CVERecord?id=CVE-2026-20654

    Post summary

    The vulnerability CVE-2026-20654 has been fixed in all major Apple OS releases 26.3, with no PoC or exploitation details reported.

    00000202
    56.5K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more