CVE-2026-20690Patch(apple / ipados)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple ipados systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.4. Processing an audio stream in a maliciously crafted media file may terminate the process.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-25); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-25: 1Mentions · 2026-03-27: 1Mentions · 2026-04-02: 1Mentions · 2026-04-15: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-02: 103-2503-2704-0204-15
Signal classification2 categories
Patch
250.0%
Disclosure
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-251
Patch1
2026-03-271
Patch1
2026-04-021
Disclosure1
2026-04-151
Disclosure1
Full discourse4 posts
  • Hossein Lotfi@hosselot
    Patch

    One vulnerability fixed in macOS Tahoe 26.4, iOS 26.4, ... : https://support.apple.com/en-us/126794 CoreMedia: CVE-2026-20690: RCE (triggerable via Apple Safari)

    Post summary

    Apple released a patch for CVE-2026-20690, a Safari‑triggerable RCE, in macOS and iOS 26.4.

    01053255.0K
    6.5K followersView on X
  • Hermes Tool@Hermes_tooll
    Patch

    One vulnerability fixed in macOS Tahoe 26.4, iOS 26.4, ... : https://support.apple.com/en-us/126794 CoreMedia: CVE-2026-20690: RCE (triggerable via Apple Safari)

    Post summary

    Apple has released macOS and iOS 26.4 updates that fix a CoreMedia RCE (CVE-2026-20690) vulnerable via Safari, with no evidence of active exploitation or PoC provided.

    0201742.5K
    3.4K followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-230|CVE-2026-20690] Apple macOS CoreMedia Framework Out-Of-Bounds Write Remote Code Execution Vulnerability (CVSS 8.8; Credit: Hossein Lotfi (@hosselot) of Trend Zero Day Initiative) https://www.zerodayinitiative.com/advisories/ZDI-26-230/

    Post summary

    Apple has disclosed CVE-2026-20690, an out-of-bounds write leading to remote code execution in macOS CoreMedia Framework, with a CVSS score of 8.8.

    00013758
    5.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-20690 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-20690 #CVE-2026-20690 #CVE   #CyberSecurity #InfoSec https://t.co/g6AXbhNyl0

    Post summary

    The tweet announces a new CVE (CVE-2026-20690) via a link to NVD, but provides no technical details, patches, or exploit information.

    0000025
    137 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more