CVE-2026-20675Disclosure(apple / ipados)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a maliciously crafted image may lead to disclosure of user information.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-12); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-02-11: 1Mentions · 2026-02-12: 3Mentions · 2026-03-13: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-03-13: 102-1102-1203-13
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-111
Disclosure1
2026-02-123
General2Patch1
2026-03-131
Disclosure1
Full discourse5 posts
  • George Karchemsky@gkarchemsky
    Disclosure

    Excited to share my first Apple CVEs in ImageIO 🎉 CVE-2026-20675 CVE-2026-20634 Thanks to Apple Product Security and Trend Micro’s Zero Day Initiative (ZDI) for the coordinated disclosure https://t.co/S4H1Bm8P57

    Post summary

    The tweet announces two new Apple ImageIO CVEs and acknowledges coordinated disclosure with Apple and ZDI, but offers no technical details, PoC, or exploitation evidence.

    590116216.0K
    204 followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Apple macOS ImageIO SGI File Parsing Integer Overflow Remote Code Execution Vulnerability (CVE-2026-20675) #Apple #ApplemacOS #CVE202620675 #CyberSecurity #RemoteCodeExecutionVulnerability https://www.systemtek.co.uk/?p=48720 https://t.co/X6On09yS7i

    Post summary

    The tweet announces the Apple macOS ImageIO SGI File Parsing Integer Overflow Remote Code Execution vulnerability (CVE-2026-20675) without providing exploit details, patches, or evidence of active exploitation.

    0000036
    1.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-20675 Memory Corruption in Apple Image Processing Across Multiple Operating Systems https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20675

    Post summary

    The snippet lists a CVE identifier and a vague title with a link, offering no substantive technical or operational details.

    0000054
    4.0K followersView on X
  • VulDB 🛡@vuldb
    General

    A new vulnerability with increased severity was disclosed for Apple macOS and other products (CVE-2026-20675) https://vuldb.com/?id.345677

    Post summary

    The text announces the existence of CVE-2026-20675 as a new, higher-severity vulnerability for macOS and other products, but provides no further technical or operational details.

    0000084
    2.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-20675 The issue was addressed with improved bounds checks. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS … https://www.cve.org/CVERecord?id=CVE-2026-20675

    Post summary

    The notice informs that CVE-2026-20675 has been addressed through improved bounds checks and lists the Apple OS versions that include the fix.

    00000234
    56.5K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more