CVE-2026-20700Patch(apple / ipados)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 105 mentions and remains active

Immediate actions

  • Patch apple ipados systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.

9.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-05. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-119

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos
  • tvos

Threat summary

  • Active exploitation appears in 171 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 305 mentions across 50 observed days

What's happening

  • Active exploitation reported across 171 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 11 signals
  • Patch or workaround mentioned in 223 signals
  • Technical details provided in 168 signals
  • General: 31 classified signals
  • Peaked 48d ago at 105 mentions (2026-02-12); latest day: 1
  • 305 total mentions across 50 days

Affected systems

Vendors
Products
ipadosiphone_osmacostvosvisionoswatchos

Deep dive

Activity timeline305 mentions / 50d
0265379105Mentions · 2026-02-11: 4Mentions · 2026-02-12: 105Mentions · 2026-02-13: 55Mentions · 2026-02-14: 7Mentions · 2026-02-15: 12Mentions · 2026-02-16: 12Mentions · 2026-02-17: 24Mentions · 2026-02-18: 9Mentions · 2026-02-19: 9Mentions · 2026-02-20: 7Mentions · 2026-02-21: 1Mentions · 2026-02-22: 3Mentions · 2026-02-24: 1Mentions · 2026-02-25: 3Mentions · 2026-02-26: 1Mentions · 2026-02-27: 2Mentions · 2026-03-05: 3Mentions · 2026-03-07: 2Mentions · 2026-03-08: 1Mentions · 2026-03-11: 1Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 3Mentions · 2026-03-16: 1Mentions · 2026-03-18: 2Mentions · 2026-03-20: 2Mentions · 2026-03-21: 1Mentions · 2026-03-22: 1Mentions · 2026-03-23: 2Mentions · 2026-03-25: 2Mentions · 2026-03-26: 1Mentions · 2026-03-28: 1Mentions · 2026-03-29: 3Mentions · 2026-03-30: 1Mentions · 2026-04-01: 1Mentions · 2026-04-12: 1Mentions · 2026-05-05: 2Mentions · 2026-05-21: 1Mentions · 2026-06-11: 1Mentions · 2026-06-28: 1Mentions · 2026-07-19: 1Mentions · 2026-07-22: 1Mentions · 2026-08-15: 1Mentions · 2026-08-20: 1Mentions · 2026-08-21: 1Mentions · 2026-09-02: 1Mentions · 2026-09-15: 1Mentions · 2026-09-29: 5Mentions · 2026-09-30: 1Mentions · 2026-10-04: 1PoC Mentioned / Linked · 2026-02-13: 2PoC Mentioned / Linked · 2026-03-05: 2PoC Mentioned / Linked · 2026-03-15: 1PoC Mentioned / Linked · 2026-03-20: 1PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-26: 1PoC Mentioned / Linked · 2026-03-29: 1PoC Mentioned / Linked · 2026-04-01: 1PoC Mentioned / Linked · 2026-06-11: 1Exploit Tool / Code · 2026-02-12: 1Exploit Tool / Code · 2026-03-20: 2Exploit Tool / Code · 2026-03-29: 1Exploit Tool / Code · 2026-03-30: 1Exploit Tool / Code · 2026-04-01: 1Active Exploitation · 2026-02-11: 2Active Exploitation · 2026-02-12: 71Active Exploitation · 2026-02-13: 22Active Exploitation · 2026-02-14: 2Active Exploitation · 2026-02-15: 8Active Exploitation · 2026-02-16: 8Active Exploitation · 2026-02-17: 17Active Exploitation · 2026-02-18: 8Active Exploitation · 2026-02-19: 4Active Exploitation · 2026-02-20: 3Active Exploitation · 2026-02-22: 1Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-02-27: 1Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-03-13: 1Active Exploitation · 2026-03-15: 1Active Exploitation · 2026-03-20: 2Active Exploitation · 2026-03-22: 1Active Exploitation · 2026-03-23: 1Active Exploitation · 2026-03-25: 1Active Exploitation · 2026-03-29: 2Active Exploitation · 2026-03-30: 1Active Exploitation · 2026-04-01: 1Active Exploitation · 2026-05-05: 2Active Exploitation · 2026-05-21: 1Active Exploitation · 2026-07-22: 1Active Exploitation · 2026-08-15: 1Active Exploitation · 2026-08-20: 1Active Exploitation · 2026-08-21: 1Active Exploitation · 2026-09-29: 3Active Exploitation · 2026-09-30: 1Patch / Workaround · 2026-02-11: 4Patch / Workaround · 2026-02-12: 86Patch / Workaround · 2026-02-13: 42Patch / Workaround · 2026-02-14: 4Patch / Workaround · 2026-02-15: 8Patch / Workaround · 2026-02-16: 10Patch / Workaround · 2026-02-17: 20Patch / Workaround · 2026-02-18: 7Patch / Workaround · 2026-02-19: 8Patch / Workaround · 2026-02-20: 6Patch / Workaround · 2026-02-21: 1Patch / Workaround · 2026-02-22: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-05: 3Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-03-29: 3Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-21: 1Patch / Workaround · 2026-07-22: 1Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-09-29: 3Patch / Workaround · 2026-09-30: 1Technical Details · 2026-02-11: 2Technical Details · 2026-02-12: 72Technical Details · 2026-02-13: 22Technical Details · 2026-02-14: 2Technical Details · 2026-02-15: 8Technical Details · 2026-02-16: 5Technical Details · 2026-02-17: 11Technical Details · 2026-02-18: 6Technical Details · 2026-02-19: 5Technical Details · 2026-02-20: 1Technical Details · 2026-02-22: 3Technical Details · 2026-02-25: 2Technical Details · 2026-02-27: 1Technical Details · 2026-03-05: 3Technical Details · 2026-03-13: 1Technical Details · 2026-03-14: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-20: 2Technical Details · 2026-03-21: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-29: 3Technical Details · 2026-03-30: 1Technical Details · 2026-04-01: 1Technical Details · 2026-05-21: 1Technical Details · 2026-06-11: 1Technical Details · 2026-08-20: 1Technical Details · 2026-08-21: 1Technical Details · 2026-09-02: 1Technical Details · 2026-09-15: 1Technical Details · 2026-09-29: 3Technical Details · 2026-09-30: 102-1102-1602-2102-2703-1303-2003-2604-1207-1909-0210-04
Signal classification6 categories
Patch
15651.5%
Active Exploitation
9029.7%
General
3110.2%
Disclosure
216.9%
Exploit
31.0%
PoC
20.7%
Referenced assets133 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-114
Patch4
2026-02-12105
Active Exploitation30Disclosure4General5Patch66
2026-02-1355
Active Exploitation14Disclosure5General5Patch31
2026-02-147
Active Exploitation1Disclosure1General2Patch3
2026-02-1512
Active Exploitation5Disclosure2Patch5
2026-02-1612
Active Exploitation6Disclosure1General1Patch4
2026-02-1724
Active Exploitation6General2Patch16
2026-02-189
Active Exploitation4General1Patch4
2026-02-199
Active Exploitation2Disclosure1Patch6
2026-02-207
General1Patch6
2026-02-211
Patch1
2026-02-223
Active Exploitation1Disclosure1General1
2026-02-241
Patch1
2026-02-253
Active Exploitation1General2
2026-02-261
General1
2026-02-272
General1Patch1
2026-03-053
Patch3
2026-03-072
General2
2026-03-081
General1
2026-03-111
Patch1
2026-03-131
Active Exploitation1
2026-03-141
Exploit1
2026-03-153
Active Exploitation1General2
2026-03-161
Patch1
2026-03-182
Disclosure1General1
2026-03-202
Active Exploitation2
2026-03-211
Patch1
2026-03-221
Active Exploitation1
2026-03-232
Active Exploitation1Disclosure1
2026-03-252
Active Exploitation1PoC1
2026-03-261
Disclosure1
2026-03-281
General1
2026-03-293
Active Exploitation1Exploit1Patch1
2026-03-301
Active Exploitation1
2026-04-011
Active Exploitation1
2026-04-121
General1
2026-05-052
Active Exploitation2
2026-05-211
Active Exploitation1
2026-06-111
PoC1
2026-06-281
Exploit1
2026-07-191
Disclosure1
2026-07-221
Active Exploitation1
2026-08-151
Active Exploitation1
2026-08-201
Active Exploitation1
2026-08-211
Patch1
2026-09-021
General1
2026-09-151
Disclosure1
2026-09-295
Active Exploitation3Disclosure1
2026-09-301
Active Exploitation1
Full discourse20 posts
  • Ali Saleh@alisalehiman
    Patch

    شرکت #اپل ساعاتی پیش از کاربران خواست به صورت فوری تمامی دستگاه ها را به نسخه 26.3 به روز رسانی کنند. این آسیب پذیری با شدت 8.8 تحت CVE-2026-20700 منتشر شده و به مهاجم اجازه اجرای کد می دهد. لطفا اطلاع رسانی بفرمایید.

    Post summary

    Apple issued an update (26.3) to address CVE-2026-20700, a high‑severity (8.8) vulnerability that permits code execution, with no indication of active exploitation or a published PoC.

    29291791301153.3K
    758 followersView on X
  • Hermes Tool@Hermes_tooll
    Exploit

    ⏳iOS Zero-Day Exploits 🩸 UpdateApple patched major zero-days in iOS 26.2 (WebKit flaws) and iOS 26.3 (CVE-2026-20700 dyld memory corruption). These were exploited in sophisticated targeted attacks on versions before 26. 🩸I have iOS 26.1 / 26.2 0-Click 🩸RCE available for testing .Who wants to test it? Contact me on Telegram: http://T.me/hermes_tooll 🩸Update to latest iOS now! #iOS #ZeroDay #CyberSecurity

    Post summary

    The post announces Apple’s patching of iOS zero‑days, reports active exploitation of CVE-2026-20700, offers a 0-click RCE PoC for iOS 26.1/26.2, and urges users to update.

    537226614146.0K
    3.4K followersView on X
  • Webtekno@webtekno
    Patch

    Apple kullanıcılarının iOS 26.3 güncellemesini acilen yüklemeleri gerekiyor. 📌Apple’a göre iOS 26.3, CVE-2026-20700 kodlu ciddi bir güvenlik açığını gideriyor. Bu açık tek başına değil, diğer zafiyetlerle birlikte kullanılarak hedef cihazlarda rastgele kod çalıştırılmasına yol açabiliyordu. 📌Risk sadece iPhone’larla sınırlı değil. iPadOS, macOS, tvOS, watchOS ve visionOS da etkileniyor. Yani Apple ekosisteminin büyük bölümü bu güvenlik zincirinin içinde.

    Post summary

    The post urges Apple users to urgently install the iOS 26.3 update, which patches CVE‑2026‑20700—a vulnerability that could enable random code execution across multiple Apple platforms.

    345225387124.4K
    503.9K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    🚨 Apple shipped emergency updates after confirming exploitation of a zero-day in dyld. The bug (CVE-2026-20700) could allow attackers to execute arbitrary code on vulnerable Apple devices. 🔗 Read: https://thehackernews.com/2026/02/apple-fixes-exploited-zero-day.html Fixes extend across iOS, macOS, visionOS, and legacy platforms.

    Post summary

    Apple released emergency updates for CVE‑2026‑20700 after confirming real‑world exploitation, with the vulnerability enabling arbitrary code execution on multiple Apple platforms.

    58082175235.8K
    1.0M followersView on X
  • YogSotho@YogSoth0
    Exploit

    #DarkSword #iOS #Exploit Chain — Six-Stage Nuclear Exploit Kit Exploit Chain: CVE-2025-31277 → CVE-2026-20700 → CVE-2025-14174 → CVE-2025-43510 → CVE-2025-43520 Target: iOS 18.4 - 18.7 (#Safari/#WebKit) Effect: Full device compromise from one click (watering hole) Privileges: Root / Kernel-level #0days #security #hacking #root #CVE

    Post summary

    The tweet announces a six‑stage exploit chain aimed at iOS Safari/WebKit (CVE‑2025‑31277, CVE‑2026‑20700, CVE‑2025‑14174, CVE‑2025‑43510, CVE‑2025‑43520) that allegedly achieves full device compromise with one click, but it offers no concrete PoC, tool details, patch information, or evidence of active use.

    113611988516.2K
    1.9K followersView on X
  • Zero Day Engineering@zerodaytraining
    Patch

    Apple recently patched the missing piece in the userland part of the Dec'25 full-chain exploit. CVE-2026-20700: dyld memory corruption to PAC bypass This bug completes the chain of CVE-2026-43529 (jsc UAF RCE, PoC public) and CVE-2026-14174 (Angle OOB EoP, no working PoC yet). Patched in iOS 26.3

    Post summary

    Apple has released a patch for CVE-2026-20700, completing the exploit chain; a PoC exists for a related CVE, but no active exploitation or false‑positive claims are mentioned.

    22301827919.7K
    10.3K followersView on X
  • yousukezan@yousukezan
    General

    Apple全OS直撃のゼロデイ「CVE-2026-20700」。なぜ「dyld」が狙われたのか高校生エンジニアが読み解く https://qiita.com/harupython/items/450fb2814af490cfa5de

    Post summary

    The article discusses Apple’s zero‑day CVE‑2026‑20700 targeting dyld, but does not provide PoC, exploit code, or patch details.

    01421247210.2K
    11.4K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 3 vulnerabilities to the KEV Catalog CVE-2025-15556: Notepad++ Download of Code Without Integrity Check Vulnerability: Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user. CVE-2026-20700: Apple Multiple Buffer Overflow Vulnerability: Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code. CVE-2024-43468: Microsoft Configuration Manager SQL Injection Vulnerability: Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.

    Post summary

    CISA announces three vulnerabilities added to its KEV catalog, providing technical details of each but no proof‑of‑concept, exploit code, or evidence of active exploitation.

    02411183715.8K
    164.8K followersView on X
  • pablito.eth 🦇🔊 ♢@PabloSabbatella
    Active Exploitation

    🚨 ALERT APPLE USERS 🚨 Update your macOS and iOS right now: Apple patched a zero-day being exploited right now. CVE-2026-20700 This issue is fixed in: - macOS Tahoe 26.3 - iOS 26.3 - iPadOS 26.3. - visionOS 26.3 - watchOS 26.3 - tvOS 26.3 https://t.co/JxyQmScFbh

    Post summary

    Apple has released a patch for CVE-2026-20700, a zero‑day that is actively exploited, across all major macOS, iOS, and related platforms.

    14294992418.1K
    82.4K followersView on X
  • dbugs@ptdbugs
    Disclosure

    iOS Exploit for Sale (CVE-2025-43529, CVE-2026-20700, CVE-2025-14174) Read on dbugs: https://dbu.gs/news/ios-exploit-for-sale-cve-2025-43529-cve-2026-20700-cve-2025-14174-20260914 Vulnerable versions: Apple iOS 15.0–18.2 Price: $10k (3 hands max), $18k (1 hand only) According to the author’s description, the exploit relies on well-known CVEs and a web trigger via the Safari browser. This implies a scenario in which the vulnerability can be triggered after opening a specially crafted webpage in Safari. CVE-2025-43529 (https://dbu.gs/vulnerability/PT-2025-51037?fts%5Bvalue%5D=CVE-2025-43529) - a use-after-free vulnerability in WebKit, where a specially crafted web page could lead to the execution of arbitrary code. CVE-2025-14174 (https://dbu.gs/vulnerability/PT-2025-50966?fts%5Bvalue%5D=CVE-2025-14174) - another WebKit vulnerability related to a memory corruption when processing malicious web content. CVE-2026-20700 (https://dbu.gs/vulnerability/PT-2026-7805?fts%5Bvalue%5D=CVE-2026-20700) — a memory corruption vulnerability in the dyld component that, when combined with an existing write-to-memory capability, could allow arbitrary code execution. iOS remains the second-largest mobile OS in the world: according to StatCounter, as of May 2026, its share of the mobile operating system market was 31,95% (https://web.telegram.org/a/%20%20%20%20https://gs.statcounter.com/os-market-share/mobile/worldwide) globally. CVE-2025-14174 — PT-2025-50966: https://dbu.gs/vulnerability/PT-2025-50966 CVE-2025-43529 — PT-2025-51037: https://dbu.gs/vulnerability/PT-2025-51037 CVE-2026-20700 — PT-2026-7805: https://dbu.gs/vulnerability/PT-2026-7805

    Post summary

    A listing advertises a bundled iOS exploit targeting CVE‑2025‑43529, CVE‑2025‑14174, and CVE‑2026‑20700 (affecting iOS 15.0‑18.2) that leverages WebKit use‑after‑free and dyld memory corruption, sold for $10k‑$18k, with no mention of active exploitation, PoC, or patch.

    7154825543.5K
    3.7K followersView on X
  • cha2ned@destr4ctt
    Disclosure

    Identified a funny bug in dyld while hunting for CVE-2026-20700 from Darksword Writeup: https://github.com/vschko/CaseStudies/tree/main/dyld-bug-jan2026

    Post summary

    A new bug in dyld was identified while hunting for CVE‑2026‑20700, with a writeup available on GitHub. No exploit, patch, or technical detail about the vulnerability is provided.

    215083536.9K
    66 followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Microsoft vulnerability CVE-2024-43468, Notepad++ vulnerability CVE-2025-15556, SolarWinds vulnerability CVE 2025-40536, & Apple vulnerability CVE-2026-20700 to our KEV Catalog. Apply mitigations to protect your org from cyberattacks. https://go.dhs.gov/Z3Q https://t.co/0hbYVOzt7p

    Post summary

    The tweet announces four CVEs added to the DHS KEV catalog, indicating they are actively exploited, and urges organizations to apply mitigations, though no PoC or patch details are provided.

    53838598.5K
    291.8K followersView on X
  • blackorbird@blackorbird
    Active Exploitation

    CVE-2026-20700(Dynamic linker): An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.

    Post summary

    The post indicates that Apple is aware of a report suggesting CVE-2026-20700 may have been exploited in targeted attacks on iOS versions before iOS 26, but it lacks evidence of a public exploit or mitigation guidance.

    090653310.5K
    39.9K followersView on X
  • Hermes Tool@Hermes_tooll
    Patch

    Apple recently patched the missing piece in the userland part of the full-chain exploit. CVE-2026-20700: dyld memory corruption to PAC bypass This bug completes the chain of CVE-2026-43529 (jsc UAF RCE, PoC public) and CVE-2026-14174 (Angle OOB EoP, no working PoC yet) Patched

    Post summary

    Apple has applied a patch to CVE-2026-20700, completing the exploit chain that includes CVE-2026-43529 (public PoC) and CVE-2026-14174 (no PoC yet). No active exploitation or false-positive claims are reported.

    08058225.3K
    1.6K followersView on X
  • Marian@marianmeyer0
    Patch

    🚨 اپل دیروز iOS 26.3 رو منتشر کرد که آسیب‌پذیری CVE-2026-20700 شدت ۸.۸ رو رفع می‌کنه. این باگ اجازه اجرای کد دلخواه رو می‌ده و گزارش‌هایی از بهره‌برداری هدفمند وجود داره. فوراً دستگاه‌هاتون رو به‌روزرسانی کنید.

    Post summary

    Apple issued iOS 26.3 to patch CVE‑2026‑20700, a vulnerability that enables arbitrary code execution, amid reports of targeted exploitation.

    1305972.9K
    16.7K followersView on X
  • 窓の杜@madonomori
    Patch

    ゼロデイ脆弱性「CVE-2026-20700」はmacOS / tvOS / watchOS / visionOSにも影響/Appleがセキュリティ更新を実施 https://forest.watch.impress.co.jp/docs/news/2085724.html https://t.co/okpJYcTLu5

    Post summary

    Apple has released a security update for the zero‑day vulnerability CVE‑2026‑20700, which affects macOS, tvOS, watchOS, and visionOS.

    02712157.2K
    86.1K followersView on X
  • Yousef@Yousef_Dev921
    Disclosure

    ماهي ثغرة (CVE-2026-20700) مكانها تحديدا في dyld (محرر الارتباط الديناميكي) وهو مسؤول عن تحميل وربط المكتبات الديناميكية في تطبيقات ويعمل في الذاكرة وتحديدا عند بدء تشغيل اي تطبيق . نوع الثغرة هو Memory Corruption وخطورتها انها تؤثر على جدار الثقة الاول باختصار السيطرة عليه تعني منح المهاجم القدرة على حقن المكتبات في عمليات النظام (نظريا) هل ممكن نشوف جيلبريك ؟ ممكن نحتاج تقريبا 4 ثغرات إضافية 1- ثغرة بداية مثل WebKit 2- كسر قيود SandBox 3- ثغرة dyld 4- ثغرة Kernel 5- وما نقدر نسوي شي في الكرينل بدون SPTM 6- تجاوز PAC او الالتفاف حوله طيب هل نقدر نسفيد منها بشكل ما ؟ لحالها لا ، لأنها سلسلة معقدة اولا نحتاج نقطة بداية لان بدونها ما نقدر نوصل لي dyld أصلا ونحتاج لكسر SandBox عشان نوصل للكيرنل ، كل هذا ممكن نظريا لان عندنا ثغرات كذا في نفس ال CVE ، ولكن ايش اهم شي باقي ؟ بالضبط SPTM + TXM وهو اهم شي لان بدونه كل الثغرات السابقة مالها اي فايدة تقريبا طيب هل ممكن نشوف TrollStore ؟ الجواب هو لا اولا ابل اغلقت كل طرق الوصول لي Root Helper الي ساعد TrollStore على العمل بصلاحيات عالية يعني نحتاج ثغرة كيرنل أساسية طيب ايش يحمي الكيرنل ؟ بالضبط SPTM + TXM هذا غير MIE يعني . باختصار هل هي ثغرة رهيبة ؟ اي هل هي في مكان حساس ؟ اي هل ممكن نشوف شي منها ؟ ممكن هل ممكن تجي ثغرة إضافية وتغير كل الكلام ؟ اي وين قوة الثغرة ؟ تحديدا في مكانها وفي انها ممكن تتجاوز PAC + KASLR لأنها تشغل قبل فرض الحمايات بالكامل . X:yousef_Dev921

    Post summary

    The text provides a disclosure of CVE-2026-20700, describing it as a memory corruption issue in dyld with potential to affect system trust, but no PoC, exploit, or patch is referenced.

    3302493.9K
    593 followersView on X
  • Keystone Hardware Wallet@KeystoneWallet
    Patch

    🚨 Mac or iPhone user? You're at risk! A zero-day flaw (CVE-2026-20700) lets attackers: • Run code on your device silently • Install spyware without a single click • Plant backdoors you'll never notice Fix: Update Apple devices now. Pass it on. Stay safe 🛡️

    Post summary

    The zero‑day vulnerability CVE‑2026‑20700 enables attackers to silently execute code and install spyware on macOS/iOS devices; users are urged to update immediately to mitigate the risk.

    1402123.9K
    63.2K followersView on X
  • HalesFall 🪽@HalesFall
    Active Exploitation

    Come post your brilliant ideas in the comments, you arrogant plonkers. Apple patched another ~30 security holes in iOS 26.6.1 with a particularly nasty one: "Processing an image may lead to arbitrary code execution" (CVE-2026-65346) You're going to get GODSTOMPED by the many men who are NOT good. Tons of iOS exploits were abused for YEARS before the "good guys" ever caught wind. Some of the flaws they were exploiting had been sitting there for DECADES. Your "security" is contingent upon the GOODWILL of other men. That is a horrible game plan. And when you lose all your money for being cute with your OPSEC, don't cry too loud. Skill Issue. The vulnerable code behind iOS CVE-2026-20700 predates the 2007 iPhone itself, having been inherited from macOS, with roots reaching back to NeXTSTEP. It was not patched until 2026. Yes, really. It was actively exploited "in the wild" by multiple threat actors, and chained together with other security holes. @tayvano_ "DARKSWORD" And before DARKSWORD, iOS was getting cucked by "CORUNA", an iOS exploit that achieves FULL DEVICE COMPROMISE. I'll repost some others (non-exhaustive) since you people glossed over them: KISMET - NSO Group FORCEDENTRY - NSO Group FINDMYPWN - NSO Group PWNYOURHOME - NSO Group ENDOFDAYS - QuaDream BLASTPASS - NSO Group OPERATION TRIANGULATION - Unknown GRAPHITE - Paragon Solutions What else is there to say? ∙ North Korea IS capable of zero-days, and chaining zero-days, but they don't need any of that to annihilate the crypto industry. They're operating at a fraction of their true power, like DragonBall Z. They send you guys poisoned PDFs, phishing links, Zoom links, and your dead bodies float down the river. It's a Graveyard of Rekt™ What battle? What defence? It's a slaughter and butcher. When "normies" clown crypto, it's accurate. It's a joke industry. There's Bitcoin, there's Ether, and there's the USD. That's it. Everything else must invent a reason to exist, in an attempt to acquire: more Bitcoin, Ether, and USD. People have been trying to "make moves" for 17 years, only to get bodied by tokenized fiat currency. KEK North Korea is a third world threat actor, not even close to being the top elite. But they don't need to elite to manhandle the crypto industry. And despite the Rekt City™ that takes place daily, the crypto industry displays the greatest hubris by far. Projects communicate through postmortems as if some profound lesson was absorbed, only to get killshotted the very next day, by some other exploit they never saw coming. You have mountains of evidence, security researchers stating the contrary, but y'all triple down that an iPhone is more secure than a Hardware Wallet. Millions of lines of code on a multimedia entertainment device vs A compact codebase on dedicated hardware that has one job Not even Apple engineers would agree with you. DONKEY. ∙ @vidya_no68665 thinks he's clever with: >"You're suppose to set the Iphone aside and only interact with it when needed not fucking daily drive it, I thought this was fucking obvious." You are grossly overestimating the security of stock iOS with absolutely nothing on it. The attack surface is MASSIVE. On iOS, your PRIVATE KEY is exposed in RAM, you retard. The Secure Enclave cannot do secp256k1 so your wallet has no choice but to decrypt and sign in memory. You are naked, AND in the AFU State which is the most vulnerable state for an iPhone. Compare that to a proper hardware wallet where the private key remains inside the Secure Element. (Do not mention Coldcard, I have a specialty dunk thread for those noob investors already, who are full of arrogance). @__noided Further, run Wireshark on a separate device and see how busy your "clean iphone" is with hundreds of connections happening in the background. It's not "quiet". Your iPhone is never idle, and it's constantly parsing untrusted data: iMessage, WebKit, ImageIO, fonts... which IS the attack surface. @n13 -- Airplane Mode is a software toggle, not a hardware kill switch. Wi-Fi/Bluetooth/Cellular/NFC/UWB run their own firmware and remain connected to the main processor. Some use DMA to access restricted regions of host memory. Now, Apple does constrain this access but they don't eliminate it. Find My literally still works against a powered off iPhone using reserve power. It broadcasts a Bluetooth Low Energy beacon that other Apple devices can pick up and relay through the Find My network. Your iPhone is still transmitting even when "off". If people want to get cute with muh "QR Codes", come on now. The iPhone can still parse attacker-controlled input, AND memory corruption bugs in image-processing code have led to RCE already. CVE-2026-65346 is a recent example, patched this week. You can presume there are others that the "good guys" haven't found yet. Why would they be notified? ∙ History Lesson: Exploit after exploit, Apple was brought to their knees. In desperation, you know what Apple did in response? They sued the NSO Group. lol lmao even "PLS STOP HACKING US, PLSSSS" And then? Apple walked away from their own lawsuit because discovery would have forced them to disclose sensitive intel that other bad actors would have weaponized against them. NSO Group aside, there's an entire black market and grey market for iOS zero days. And these upstanding scholars are not buying exploits to report them to Apple. They are going to use them to destroy you, for as long as possible until they're patched, if ever. If they're lucky, they can use it for YEARS. "In the wild" simply means "the good guys finally noticed bro". Great plan, everyone. Good work. Guess who discovers tons of iOS zero-days? Google Citizen Lab Amnesty Kaspersky Numerous independent researchers Anonymous reports Often, it's not even Apple themselves. Your goodwill is stacked on top of goodwill from people who have zero obligation to Apple. Y'all have no clue if it was exploited or not because not everyone is reporting they got Rekt™. And, you have no idea if you were exploited when it concerns zero-days. It can execute and persist, without you noticing. @SatoshiSideho -- Apple has been getting Rekt™ for years @bch_gangster -- Zach does great work and I'm not knocking that. But he's a self-taught on-chain investigator, not a cryptographer, and he's never claimed otherwise. He has social reach, and you're citing him on something outside his expertise. People can be wrong, you know? ∙ The amusing thing is I dunk on hardware wallets all the time, targeting their actual weaknesses unrelated to noob skill issues. Go read them. I've been citing iPhones & Pixels well before Zach's post, and well before any KOL reacted to "timeline news". Y'all have this notion that I don't have a plethora of tools at my disposal and have reached a sound conclusion based on hard evidence, and BATTLE EXPERIENCE. I don't need a job, your job, or any referral links. I can speak with the most freedom, uninhibited by bias. Meanwhile, dudes clinging onto their sole iPhone are looking for confirmation bias.

    Post summary

    The text asserts that Apple’s iOS vulnerabilities—particularly CVE‑2026‑20700 and CVE‑2026‑65346—are being actively exploited in the wild while noting that patches have been released.

    6021185.4K
    411 followersView on X
  • Josh Long (the JoshMeister)@theJoshMeister
    Patch

    Key insight: Apple ONLY patched CVE-2026-20700 (which was reportedly exploited in the wild) for iOS, iPadOS, macOS, tvOS, watchOS, & visionOS 26.3. ⚠️ If you’re still on iOS 18 or earlier, or any macOS before Tahoe, you’re missing out on critically important security updates.

    Post summary

    Apple has issued a patch for CVE‑2026‑20700, which was reported to have been exploited in the wild, and users on older iOS and macOS versions must upgrade to protect against this vulnerability.

    0111583.1K
    152.4K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---
OSappletvos---
OSapplevisionos---
OSapplewatchos---

Explore more