Exploitation observed; activity peaked at 105 mentions and remains active
Immediate actions
Patch apple ipados systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-05. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
شرکت #اپل ساعاتی پیش از کاربران خواست به صورت فوری تمامی دستگاه ها را به نسخه 26.3 به روز رسانی کنند.
این آسیب پذیری با شدت 8.8 تحت CVE-2026-20700 منتشر شده و به مهاجم اجازه اجرای کد می دهد.
لطفا اطلاع رسانی بفرمایید.
Post summary
Apple issued an update (26.3) to address CVE-2026-20700, a high‑severity (8.8) vulnerability that permits code execution, with no indication of active exploitation or a published PoC.
⏳iOS Zero-Day Exploits 🩸
UpdateApple patched major zero-days in iOS 26.2 (WebKit flaws) and iOS 26.3 (CVE-2026-20700 dyld memory corruption). These were exploited in sophisticated targeted attacks on versions before 26.
🩸I have iOS 26.1 / 26.2 0-Click 🩸RCE available for testing
.Who wants to test it?
Contact me on Telegram: http://T.me/hermes_tooll
🩸Update to latest iOS now! #iOS#ZeroDay#CyberSecurity
Post summary
The post announces Apple’s patching of iOS zero‑days, reports active exploitation of CVE-2026-20700, offers a 0-click RCE PoC for iOS 26.1/26.2, and urges users to update.
Apple kullanıcılarının iOS 26.3 güncellemesini acilen yüklemeleri gerekiyor.
📌Apple’a göre iOS 26.3, CVE-2026-20700 kodlu ciddi bir güvenlik açığını gideriyor. Bu açık tek başına değil, diğer zafiyetlerle birlikte kullanılarak hedef cihazlarda rastgele kod çalıştırılmasına yol açabiliyordu.
📌Risk sadece iPhone’larla sınırlı değil. iPadOS, macOS, tvOS, watchOS ve visionOS da etkileniyor. Yani Apple ekosisteminin büyük bölümü bu güvenlik zincirinin içinde.
Post summary
The post urges Apple users to urgently install the iOS 26.3 update, which patches CVE‑2026‑20700—a vulnerability that could enable random code execution across multiple Apple platforms.
🚨 Apple shipped emergency updates after confirming exploitation of a zero-day in dyld.
The bug (CVE-2026-20700) could allow attackers to execute arbitrary code on vulnerable Apple devices.
🔗 Read: https://thehackernews.com/2026/02/apple-fixes-exploited-zero-day.html
Fixes extend across iOS, macOS, visionOS, and legacy platforms.
Post summary
Apple released emergency updates for CVE‑2026‑20700 after confirming real‑world exploitation, with the vulnerability enabling arbitrary code execution on multiple Apple platforms.
The tweet announces a six‑stage exploit chain aimed at iOS Safari/WebKit (CVE‑2025‑31277, CVE‑2026‑20700, CVE‑2025‑14174, CVE‑2025‑43510, CVE‑2025‑43520) that allegedly achieves full device compromise with one click, but it offers no concrete PoC, tool details, patch information, or evidence of active use.
Apple recently patched the missing piece in the userland part of the Dec'25 full-chain exploit.
CVE-2026-20700: dyld memory corruption to PAC bypass
This bug completes the chain of CVE-2026-43529 (jsc UAF RCE, PoC public) and CVE-2026-14174 (Angle OOB EoP, no working PoC yet).
Patched in iOS 26.3
Post summary
Apple has released a patch for CVE-2026-20700, completing the exploit chain; a PoC exists for a related CVE, but no active exploitation or false‑positive claims are mentioned.
‼️ CISA has added 3 vulnerabilities to the KEV Catalog
CVE-2025-15556: Notepad++ Download of Code Without Integrity Check Vulnerability: Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept or redirect update traffic to download and execute an attacker-controlled installer. This could lead to arbitrary code execution with the privileges of the user.
CVE-2026-20700: Apple Multiple Buffer Overflow Vulnerability: Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code.
CVE-2024-43468: Microsoft Configuration Manager SQL Injection Vulnerability: Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database.
Post summary
CISA announces three vulnerabilities added to its KEV catalog, providing technical details of each but no proof‑of‑concept, exploit code, or evidence of active exploitation.
🚨 ALERT APPLE USERS 🚨
Update your macOS and iOS right now: Apple patched a zero-day being exploited right now.
CVE-2026-20700
This issue is fixed in:
- macOS Tahoe 26.3
- iOS 26.3
- iPadOS 26.3.
- visionOS 26.3
- watchOS 26.3
- tvOS 26.3 https://t.co/JxyQmScFbh
Post summary
Apple has released a patch for CVE-2026-20700, a zero‑day that is actively exploited, across all major macOS, iOS, and related platforms.
iOS Exploit for Sale (CVE-2025-43529, CVE-2026-20700, CVE-2025-14174)
Read on dbugs: https://dbu.gs/news/ios-exploit-for-sale-cve-2025-43529-cve-2026-20700-cve-2025-14174-20260914
Vulnerable versions: Apple iOS 15.0–18.2
Price: $10k (3 hands max), $18k (1 hand only)
According to the author’s description, the exploit relies on well-known CVEs and a web trigger via the Safari browser. This implies a scenario in which the vulnerability can be triggered after opening a specially crafted webpage in Safari.
CVE-2025-43529 (https://dbu.gs/vulnerability/PT-2025-51037?fts%5Bvalue%5D=CVE-2025-43529) - a use-after-free vulnerability in WebKit, where a specially crafted web page could lead to the execution of arbitrary code.
CVE-2025-14174 (https://dbu.gs/vulnerability/PT-2025-50966?fts%5Bvalue%5D=CVE-2025-14174) - another WebKit vulnerability related to a memory corruption when processing malicious web content.
CVE-2026-20700 (https://dbu.gs/vulnerability/PT-2026-7805?fts%5Bvalue%5D=CVE-2026-20700) — a memory corruption vulnerability in the dyld component that, when combined with an existing write-to-memory capability, could allow arbitrary code execution.
iOS remains the second-largest mobile OS in the world: according to StatCounter, as of May 2026, its share of the mobile operating system market was 31,95% (https://web.telegram.org/a/%20%20%20%20https://gs.statcounter.com/os-market-share/mobile/worldwide) globally.
CVE-2025-14174 — PT-2025-50966: https://dbu.gs/vulnerability/PT-2025-50966
CVE-2025-43529 — PT-2025-51037: https://dbu.gs/vulnerability/PT-2025-51037
CVE-2026-20700 — PT-2026-7805: https://dbu.gs/vulnerability/PT-2026-7805
Post summary
A listing advertises a bundled iOS exploit targeting CVE‑2025‑43529, CVE‑2025‑14174, and CVE‑2026‑20700 (affecting iOS 15.0‑18.2) that leverages WebKit use‑after‑free and dyld memory corruption, sold for $10k‑$18k, with no mention of active exploitation, PoC, or patch.
Identified a funny bug in dyld while hunting for CVE-2026-20700 from Darksword
Writeup: https://github.com/vschko/CaseStudies/tree/main/dyld-bug-jan2026
Post summary
A new bug in dyld was identified while hunting for CVE‑2026‑20700, with a writeup available on GitHub. No exploit, patch, or technical detail about the vulnerability is provided.
🛡️ We added Microsoft vulnerability CVE-2024-43468, Notepad++ vulnerability CVE-2025-15556, SolarWinds vulnerability CVE 2025-40536, & Apple vulnerability CVE-2026-20700 to our KEV Catalog. Apply mitigations to protect your org from cyberattacks. https://go.dhs.gov/Z3Q https://t.co/0hbYVOzt7p
Post summary
The tweet announces four CVEs added to the DHS KEV catalog, indicating they are actively exploited, and urges organizations to apply mitigations, though no PoC or patch details are provided.
CVE-2026-20700(Dynamic linker):
An attacker with memory write capability may be able to execute arbitrary code.
Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.
Post summary
The post indicates that Apple is aware of a report suggesting CVE-2026-20700 may have been exploited in targeted attacks on iOS versions before iOS 26, but it lacks evidence of a public exploit or mitigation guidance.
Apple recently patched the missing piece in the userland part of the full-chain exploit.
CVE-2026-20700: dyld memory corruption to PAC bypass
This bug completes the chain of CVE-2026-43529 (jsc UAF RCE, PoC public) and CVE-2026-14174 (Angle OOB EoP, no working PoC yet)
Patched
Post summary
Apple has applied a patch to CVE-2026-20700, completing the exploit chain that includes CVE-2026-43529 (public PoC) and CVE-2026-14174 (no PoC yet). No active exploitation or false-positive claims are reported.
🚨 اپل دیروز iOS 26.3 رو منتشر کرد که آسیبپذیری CVE-2026-20700 شدت ۸.۸ رو رفع میکنه.
این باگ اجازه اجرای کد دلخواه رو میده و گزارشهایی از بهرهبرداری هدفمند وجود داره. فوراً دستگاههاتون رو بهروزرسانی کنید.
Post summary
Apple issued iOS 26.3 to patch CVE‑2026‑20700, a vulnerability that enables arbitrary code execution, amid reports of targeted exploitation.
ماهي ثغرة (CVE-2026-20700)
مكانها تحديدا في dyld (محرر الارتباط الديناميكي) وهو مسؤول عن تحميل وربط المكتبات الديناميكية في تطبيقات ويعمل في الذاكرة وتحديدا عند بدء تشغيل اي تطبيق .
نوع الثغرة هو Memory Corruption
وخطورتها انها تؤثر على جدار الثقة الاول باختصار السيطرة عليه تعني منح المهاجم القدرة على حقن المكتبات في عمليات النظام (نظريا)
هل ممكن نشوف جيلبريك ؟
ممكن نحتاج تقريبا 4 ثغرات إضافية
1- ثغرة بداية مثل WebKit
2- كسر قيود SandBox
3- ثغرة dyld
4- ثغرة Kernel
5- وما نقدر نسوي شي في الكرينل بدون SPTM
6- تجاوز PAC او الالتفاف حوله
طيب هل نقدر نسفيد منها بشكل ما ؟
لحالها لا ، لأنها سلسلة معقدة
اولا نحتاج نقطة بداية لان بدونها ما نقدر نوصل لي dyld أصلا ونحتاج لكسر SandBox عشان نوصل للكيرنل ، كل هذا ممكن نظريا لان عندنا ثغرات كذا في نفس ال CVE ، ولكن ايش اهم شي باقي ؟ بالضبط SPTM + TXM وهو اهم شي لان بدونه كل الثغرات السابقة مالها اي فايدة تقريبا
طيب هل ممكن نشوف TrollStore ؟
الجواب هو لا
اولا ابل اغلقت كل طرق الوصول لي Root Helper الي ساعد TrollStore على العمل بصلاحيات عالية يعني نحتاج ثغرة كيرنل أساسية طيب ايش يحمي الكيرنل ؟ بالضبط SPTM + TXM هذا غير MIE يعني .
باختصار
هل هي ثغرة رهيبة ؟ اي
هل هي في مكان حساس ؟ اي
هل ممكن نشوف شي منها ؟ ممكن
هل ممكن تجي ثغرة إضافية وتغير كل الكلام ؟ اي
وين قوة الثغرة ؟ تحديدا في مكانها وفي انها ممكن تتجاوز PAC + KASLR لأنها تشغل قبل فرض الحمايات بالكامل .
X:yousef_Dev921
Post summary
The text provides a disclosure of CVE-2026-20700, describing it as a memory corruption issue in dyld with potential to affect system trust, but no PoC, exploit, or patch is referenced.
🚨 Mac or iPhone user? You're at risk!
A zero-day flaw (CVE-2026-20700) lets attackers:
• Run code on your device silently
• Install spyware without a single click
• Plant backdoors you'll never notice
Fix: Update Apple devices now.
Pass it on. Stay safe 🛡️
Post summary
The zero‑day vulnerability CVE‑2026‑20700 enables attackers to silently execute code and install spyware on macOS/iOS devices; users are urged to update immediately to mitigate the risk.
Come post your brilliant ideas in the comments, you arrogant plonkers.
Apple patched another ~30 security holes in iOS 26.6.1 with a particularly nasty one: "Processing an image may lead to arbitrary code execution" (CVE-2026-65346)
You're going to get GODSTOMPED by the many men who are NOT good. Tons of iOS exploits were abused for YEARS before the "good guys" ever caught wind. Some of the flaws they were exploiting had been sitting there for DECADES.
Your "security" is contingent upon the GOODWILL of other men.
That is a horrible game plan. And when you lose all your money for being cute with your OPSEC, don't cry too loud.
Skill Issue.
The vulnerable code behind iOS CVE-2026-20700 predates the 2007 iPhone itself, having been inherited from macOS, with roots reaching back to NeXTSTEP. It was not patched until 2026. Yes, really.
It was actively exploited "in the wild" by multiple threat actors, and chained together with other security holes. @tayvano_
"DARKSWORD"
And before DARKSWORD, iOS was getting cucked by "CORUNA", an iOS exploit that achieves FULL DEVICE COMPROMISE.
I'll repost some others (non-exhaustive) since you people glossed over them:
KISMET - NSO Group
FORCEDENTRY - NSO Group
FINDMYPWN - NSO Group
PWNYOURHOME - NSO Group
ENDOFDAYS - QuaDream
BLASTPASS - NSO Group
OPERATION TRIANGULATION - Unknown
GRAPHITE - Paragon Solutions
What else is there to say?
∙
North Korea IS capable of zero-days, and chaining zero-days, but they don't need any of that to annihilate the crypto industry. They're operating at a fraction of their true power, like DragonBall Z.
They send you guys poisoned PDFs, phishing links, Zoom links, and your dead bodies float down the river.
It's a Graveyard of Rekt™
What battle? What defence? It's a slaughter and butcher.
When "normies" clown crypto, it's accurate. It's a joke industry. There's Bitcoin, there's Ether, and there's the USD. That's it.
Everything else must invent a reason to exist, in an attempt to acquire: more Bitcoin, Ether, and USD. People have been trying to "make moves" for 17 years, only to get bodied by tokenized fiat currency.
KEK
North Korea is a third world threat actor, not even close to being the top elite. But they don't need to elite to manhandle the crypto industry.
And despite the Rekt City™ that takes place daily, the crypto industry displays the greatest hubris by far.
Projects communicate through postmortems as if some profound lesson was absorbed, only to get killshotted the very next day, by some other exploit they never saw coming.
You have mountains of evidence, security researchers stating the contrary, but y'all triple down that an iPhone is more secure than a Hardware Wallet.
Millions of lines of code on a multimedia entertainment device
vs
A compact codebase on dedicated hardware that has one job
Not even Apple engineers would agree with you.
DONKEY.
∙
@vidya_no68665 thinks he's clever with:
>"You're suppose to set the Iphone aside and only interact with it when needed not fucking daily drive it, I thought this was fucking obvious."
You are grossly overestimating the security of stock iOS with absolutely nothing on it. The attack surface is MASSIVE.
On iOS, your PRIVATE KEY is exposed in RAM, you retard. The Secure Enclave cannot do secp256k1 so your wallet has no choice but to decrypt and sign in memory. You are naked, AND in the AFU State which is the most vulnerable state for an iPhone.
Compare that to a proper hardware wallet where the private key remains inside the Secure Element. (Do not mention Coldcard, I have a specialty dunk thread for those noob investors already, who are full of arrogance). @__noided
Further, run Wireshark on a separate device and see how busy your "clean iphone" is with hundreds of connections happening in the background. It's not "quiet". Your iPhone is never idle, and it's constantly parsing untrusted data: iMessage, WebKit, ImageIO, fonts... which IS the attack surface.
@n13 -- Airplane Mode is a software toggle, not a hardware kill switch. Wi-Fi/Bluetooth/Cellular/NFC/UWB run their own firmware and remain connected to the main processor. Some use DMA to access restricted regions of host memory. Now, Apple does constrain this access but they don't eliminate it.
Find My literally still works against a powered off iPhone using reserve power. It broadcasts a Bluetooth Low Energy beacon that other Apple devices can pick up and relay through the Find My network. Your iPhone is still transmitting even when "off".
If people want to get cute with muh "QR Codes", come on now. The iPhone can still parse attacker-controlled input, AND memory corruption bugs in image-processing code have led to RCE already. CVE-2026-65346 is a recent example, patched this week. You can presume there are others that the "good guys" haven't found yet. Why would they be notified?
∙
History Lesson:
Exploit after exploit, Apple was brought to their knees.
In desperation, you know what Apple did in response?
They sued the NSO Group.
lol lmao even
"PLS STOP HACKING US, PLSSSS"
And then? Apple walked away from their own lawsuit because discovery would have forced them to disclose sensitive intel that other bad actors would have weaponized against them.
NSO Group aside, there's an entire black market and grey market for iOS zero days. And these upstanding scholars are not buying exploits to report them to Apple. They are going to use them to destroy you, for as long as possible until they're patched, if ever. If they're lucky, they can use it for YEARS.
"In the wild" simply means "the good guys finally noticed bro".
Great plan, everyone. Good work.
Guess who discovers tons of iOS zero-days?
Google
Citizen Lab
Amnesty
Kaspersky
Numerous independent researchers
Anonymous reports
Often, it's not even Apple themselves.
Your goodwill is stacked on top of goodwill from people who have zero obligation to Apple.
Y'all have no clue if it was exploited or not because not everyone is reporting they got Rekt™. And, you have no idea if you were exploited when it concerns zero-days. It can execute and persist, without you noticing.
@SatoshiSideho -- Apple has been getting Rekt™ for years
@bch_gangster -- Zach does great work and I'm not knocking that. But he's a self-taught on-chain investigator, not a cryptographer, and he's never claimed otherwise. He has social reach, and you're citing him on something outside his expertise. People can be wrong, you know?
∙
The amusing thing is I dunk on hardware wallets all the time, targeting their actual weaknesses unrelated to noob skill issues. Go read them.
I've been citing iPhones & Pixels well before Zach's post, and well before any KOL reacted to "timeline news".
Y'all have this notion that I don't have a plethora of tools at my disposal and have reached a sound conclusion based on hard evidence, and BATTLE EXPERIENCE.
I don't need a job, your job, or any referral links. I can speak with the most freedom, uninhibited by bias.
Meanwhile, dudes clinging onto their sole iPhone are looking for confirmation bias.
Post summary
The text asserts that Apple’s iOS vulnerabilities—particularly CVE‑2026‑20700 and CVE‑2026‑65346—are being actively exploited in the wild while noting that patches have been released.
Key insight: Apple ONLY patched CVE-2026-20700 (which was reportedly exploited in the wild) for iOS, iPadOS, macOS, tvOS, watchOS, & visionOS 26.3.
⚠️ If you’re still on iOS 18 or earlier, or any macOS before Tahoe, you’re missing out on critically important security updates.
Post summary
Apple has issued a patch for CVE‑2026‑20700, which was reported to have been exploited in the wild, and users on older iOS and macOS versions must upgrade to protect against this vulnerability.