CVE-2026-20687PoC(apple / ipados)

MEDIUMCVSS 7.1 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for apple ipados systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, watchOS 26.4. An app may be able to cause unexpected system termination or write kernel memory.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-03-24); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvoswatchos

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-24: 1Mentions · 2026-04-06: 1Mentions · 2026-04-13: 1Mentions · 2026-04-15: 1PoC Mentioned / Linked · 2026-03-24: 1PoC Mentioned / Linked · 2026-04-06: 1Exploit Tool / Code · 2026-03-24: 1Exploit Tool / Code · 2026-04-06: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-13: 103-2404-0604-1304-15
Signal classification3 categories
PoC
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-241
PoC1
2026-04-061
PoC1
2026-04-131
Disclosure1
2026-04-151
General1
Full discourse4 posts
  • johnny@zeroxjf
    Disclosure

    One part of using AI to find vulns is I literally find so much stuff I lose track at times. CVE-2026-20687 was issued in response to an AppleJPEGDriver UAF I found, but I just rediscovered a derivative of that initial bug in a harness I built, and it’s still present in iOS 26.4.1 https://t.co/D0rlJ4kKzK

    Post summary

    The user reports a use‑after‑free vulnerability (CVE-2026-20687) in AppleJPEGDriver, notes a related bug still present in iOS 26.4.1, but provides no PoC, exploit code, or patch details.

    31501413712.1K
    4.2K followersView on X
  • johnny@zeroxjf
    PoC

    @MorenCubed https://github.com/zeroxjf/CVE-2026-20687-AppleSEPKeyStore-UAF

    Post summary

    The tweet links to a GitHub repository, indicating that a proof‑of‑concept for CVE‑2026‑20687 has been shared, but no evidence of active exploitation or patching is provided.

    15045224.3K
    2.8K followersView on X
  • johnny@zeroxjf
    PoC

    For those interested: CVE-2026-20637 — AppleSEPKeyStore UAF https://github.com/zeroxjf/CVE-2026-20637-AppleSEPKeyStore-UAF CVE-2026-20687 — AppleJPEGDriver UAF https://github.com/zeroxjf/CVE-2026-20687-AppleJPEGDriver-UAF

    Post summary

    The text shares GitHub links to proof‑of‑concept or exploit code for two Apple use‑after‑free CVEs, highlighting the vulnerabilities but not indicating active exploitation or patch status.

    38132173.7K
    4.1K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-20687 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-20687 #CVE-2026-20687 #CVE   #CyberSecurity #InfoSec https://t.co/McvWzZe29W

    Post summary

    A brief alert announcing CVE-2026-20687 with minimal information and no additional details.

    0000034
    137 followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplewatchos---

Explore more