Hossein Lotfi@hosselotPatch
Apple released a patch for CVE-2026-20690, a Safari‑triggerable RCE, in macOS and iOS 26.4.
Hermes Tool@Hermes_toollPatch
Apple has released macOS and iOS 26.4 updates that fix a CoreMedia RCE (CVE-2026-20690) vulnerable via Safari, with no evidence of active exploitation or PoC provided.
TheZDIBugs@TheZDIBugsDisclosure
Apple has disclosed CVE-2026-20690, an out-of-bounds write leading to remote code execution in macOS CoreMedia Framework, with a CVSS score of 8.8.
CVEarity@CVEarityDisclosure
The tweet announces a new CVE (CVE-2026-20690) via a link to NVD, but provides no technical details, patches, or exploit information.