CVE-2026-20695Disclosure(apple / macos)

LOWCVSS 6.2 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple macos systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

An information disclosure issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to determine kernel memory layout.

2.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-25); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
macos

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-25: 1Mentions · 2026-04-15: 1Mentions · 2026-07-08: 1PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-07-08: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-08: 103-2504-1507-08
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-251
Disclosure1
2026-04-151
General1
2026-07-081
Disclosure1
Full discourse3 posts
  • MacSec Labs@MacSecLabs
    Disclosure

    We found a KASLR bypass in macOS IOKit. Two services leaked live kernel heap addresses to any unprivileged, sandboxed user. Apple Security Bounty, CVE-2026-20695, fixed in macOS Tahoe 26.4. This is the exact process we teach in our new course: macOS Kernel Vulnerability Research. Built from 10+ years of real bounty hunting on the kernel and beyond, not theory. Course: https://macseclabs.com/curriculum?course=macos-kernel-vulnerability-research Writeup: https://hxr1.ghost.io/leaking-the-kernel-a-kaslr-bypass-in-macos-iokit/ #RedTeam #macOS #OffensiveSecurity #CyberSecurity #InfoSec #EthicalHacking #PenTesting #SecurityTraining #BugBounty

    Post summary

    The post announces the discovery of a KASLR bypass in macOS IOKit (CVE‑2026‑20695), notes its patch in macOS Tahoe 26.4, and links to a writeup providing a PoC, framing it as a new vulnerability disclosure.

    2220122799.5K
    387 followersView on X
  • DongHa Lee@gap_dev
    Disclosure

    🍎CVE-2026-20695 XNU bug! [ZDI-CAN-28499] https://t.co/E5Od8VhmeX

    Post summary

    The tweet announces CVE-2026-20695, an XNU bug, and directs users to a ZDI advisory link, but does not share exploit code, patch information, or technical details.

    0403662.3K
    387 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-20695 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-20695 #CVE-2026-20695 #CVE   #CyberSecurity #InfoSec https://t.co/uwVwz9G5Ch

    Post summary

    A brief announcement of CVE-2026-20695 with a reference to the NVD page; no additional details or actionable information are provided.

    0000026
    137 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---

Explore more