
Apple’s February 11, 2026 security updates include a fix for a Photos vulnerability that could let someone with physical access to a locked iPhone or iPad view photos from the lock screen. Apple says the issue (CVE-2026-20642, credited to Dalibor Milanovic) was caused by an input validation flaw and is addressed in iOS 26.3 and iPadOS 26.3 for iPhone 11 and later and several recent iPad models. In a separate patch, Apple fixed a Safari logic issue that could allow an app to access a user’s Safari browsing history. The flaw (CVE-2026-20656, credited to Mickey Jin) was resolved with improved validation and is listed in iOS 18.7.5/iPadOS 18.7.5 for iPhone XS/XS Max/XR and iPad (7th gen), as well as Safari 26.3 on macOS Sonoma and macOS Sequoia. Users are advised to update promptly to reduce privacy risk.
Post summary
Apple released updates for CVE‑2026‑20642 and CVE‑2026‑20656, fixing Photos lock‑screen photo leakage and Safari history exposure, and urged users to apply the new iOS and iPadOS patches promptly.


