
Apple recently patched the missing piece in the userland part of the Dec'25 full-chain exploit. CVE-2026-20700: dyld memory corruption to PAC bypass This bug completes the chain of CVE-2026-43529 (jsc UAF RCE, PoC public) and CVE-2026-14174 (Angle OOB EoP, no working PoC yet). Patched in iOS 26.3
Post summary
Apple has released a patch (iOS 26.3) that closes the missing user‑land component of a series of linked exploits, notably CVE‑2026‑20700 which exploits dyld memory corruption to bypass PAC.


