CVE-2026-20677Patch(apple / ipados)

LOWCVSS 9.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • visionos

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Peaked 1d ago at 2 mentions (2026-02-12); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacosvisionos

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-12: 2Mentions · 2026-02-24: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-12: 2Technical Details · 2026-02-24: 102-1202-24
Signal classification1 categories
Patch
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-122
Patch2
2026-02-241
Patch1
Full discourse3 posts
  • Wazuh@wazuh
    Patch

    Apple macOS, iOS, iPadOS, and visionOS are affected by CVE-2026-20677 (CVSS 9.0 – Critical), a symbolic link sandbox bypass. Update to macOS 14.8.4/26.3, iOS/iPadOS 18.7.5/26.3, and visionOS 26.3 now. Read more: https://ow.ly/uC2050YkWK2 https://t.co/vdAGc1yG3t

    Post summary

    Apple has issued updates for macOS, iOS, iPadOS, and visionOS to address CVE‑2026‑20677, a critical symbolic link sandbox bypass. Users are advised to install the latest patches (macOS 14.8.4/26.3, iOS/iPadOS 18.7.5/26.3, visionOS 26.3).

    070134720
    7.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Patch

    CVE-2026-20677 Sandbox Bypass Race Condition in Apple Operating Systems Resolved https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20677

    Post summary

    CVE-2026-20677, a sandbox bypass race condition in Apple OS, has been marked as resolved, but no patch details, PoC, or exploitation evidence are provided.

    0000059
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-20677 A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Tahoe 26.3, macOS Sonoma 14.8.4, iOS 18.7.5 and iPadOS 18.7.5, v… https://www.cve.org/CVERecord?id=CVE-2026-20677

    Post summary

    CVE-2026-20677 is a race condition with symbolic links, fixed in specific macOS, iOS, and iPadOS versions; no PoC or exploit details are provided.

    00000310
    56.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSapplevisionos---

Explore more