CVE-2026-20656Patch(apple / ipados)

LOWCVSS 3.3 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3. An app may be able to access a user's Safari history.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • safari

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
ipadosiphone_osmacossafari

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-12: 3Patch / Workaround · 2026-02-12: 3Technical Details · 2026-02-12: 202-12
Signal classification1 categories
Patch
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • Hespress English@HespressEnglish
    Patch

    Apple’s February 11, 2026 security updates include a fix for a Photos vulnerability that could let someone with physical access to a locked iPhone or iPad view photos from the lock screen. Apple says the issue (CVE-2026-20642, credited to Dalibor Milanovic) was caused by an input validation flaw and is addressed in iOS 26.3 and iPadOS 26.3 for iPhone 11 and later and several recent iPad models. In a separate patch, Apple fixed a Safari logic issue that could allow an app to access a user’s Safari browsing history. The flaw (CVE-2026-20656, credited to Mickey Jin) was resolved with improved validation and is listed in iOS 18.7.5/iPadOS 18.7.5 for iPhone XS/XS Max/XR and iPad (7th gen), as well as Safari 26.3 on macOS Sonoma and macOS Sequoia. Users are advised to update promptly to reduce privacy risk.

    Post summary

    Apple released updates for CVE‑2026‑20642 and CVE‑2026‑20656, fixing Photos lock‑screen photo leakage and Safari history exposure, and urged users to apply the new iOS and iPadOS patches promptly.

    00000146
    2.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2026-20656 Safari History Disclosure Vulnerability in Apple Platforms Addressed in iOS 18.7.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20656

    Post summary

    The post reports CVE‑2026‑20656, a Safari history disclosure vulnerability, and notes that it has been fixed in iOS 18.7.5.

    0000085
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-20656 A logic issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, Safari 26.3, macOS Tahoe 26.3. An app may be able to access… https://www.cve.org/CVERecord?id=CVE-2026-20656

    Post summary

    The text announces that CVE-2026-20656 has been fixed in the latest OS and browser versions, providing a patch update.

    00000295
    56.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
Appapplesafari---

Explore more