
One part of using AI to find vulns is I literally find so much stuff I lose track at times. CVE-2026-20687 was issued in response to an AppleJPEGDriver UAF I found, but I just rediscovered a derivative of that initial bug in a harness I built, and it’s still present in iOS 26.4.1 https://t.co/D0rlJ4kKzK
Post summary
The user reports a use‑after‑free vulnerability (CVE-2026-20687) in AppleJPEGDriver, notes a related bug still present in iOS 26.4.1, but provides no PoC, exploit code, or patch details.

