Advisories
visionOSExploitedCISA KEV listedCRITICAL2026-02-11
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary...
CVEs:CVE-2026-20700
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)HIGH2026-02-11
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A remote attacker may be able to cause a denial-of-service.
CVEs:CVE-2026-20652
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2026-02-11
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3. Processing a maliciously crafted string may lead to heap corruption.
CVEs:CVE-2026-20639
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)CRITICAL2026-02-11
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. Processing a maliciously crafted USD file may lead to unexpected app te...
CVEs:CVE-2026-20616
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)HIGH2026-02-11
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to perform denial-of-s...
CVEs:CVE-2026-20650
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)HIGH2026-02-11
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected pro...
CVEs:CVE-2026-20644
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)CRITICAL2026-02-11
A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restr...
CVEs:CVE-2026-20677
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)HIGH2026-02-11
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a malici...
CVEs:CVE-2026-20675
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)HIGH2026-02-11
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3. A user may be able to view sensitive user information.
CVEs:CVE-2026-20649
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)MEDIUM2026-02-11
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.
CVEs:CVE-2026-20651
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)HIGH2026-02-11
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An attacker may be able to cause unexpected system termination or read kernel memory.
CVEs:CVE-2026-20620
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2026-02-11
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges.
CVEs:CVE-2026-20610
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)CRITICAL2026-02-11
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An...
CVEs:CVE-2026-20637
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)HIGH2026-02-11
This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Sonoma 14.8.5, macOS Tahoe 26.3, macOS Tahoe 26.4. An app may be able t...
CVEs:CVE-2026-20694
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)MEDIUM2026-02-11
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitiv...
CVEs:CVE-2026-20668
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2026-02-11
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to gain root privileges.
CVEs:CVE-2026-20614
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)CRITICAL2026-02-11
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to gain root privileges.
CVEs:CVE-2026-20615
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)HIGH2026-02-11
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, macOS Tahoe 26.4. An app may be able to access user-sensi...
CVEs:CVE-2026-20699
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSActive exploitation (sightings)HIGH2026-02-11
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, watchOS 26.3. An app may be able to break out of its sandbox.
CVEs:CVE-2026-20667
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)MEDIUM2026-02-11
The issue was addressed with improved memory handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system termination.
CVEs:CVE-2026-20654
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSActive exploitation (sightings)CRITICAL2026-02-11
A package validation issue was addressed by blocking the vulnerable package. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges.
CVEs:CVE-2026-20658
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)CRITICAL2026-02-11
This issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Tahoe 26.3, visionOS 26.3. A malicious app may be able to gain root privileges.
CVEs:CVE-2026-20626
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)HIGH2026-02-11
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a mali...
CVEs:CVE-2026-20609
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)HIGH2026-02-11
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app m...
CVEs:CVE-2026-20628
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
visionOSActive exploitation (sightings)CRITICAL2026-02-11
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to gain root privileges.
CVEs:CVE-2026-20617
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
visionOSPoC exploitHIGH2026-02-11
A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A remote user may be able t...
CVEs:CVE-2026-20660
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2026-02-11
A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.2 and iPadOS 26.2. Restoring a maliciously crafted backup file may lead to modification of protected system files.
CVEs:CVE-2025-43537
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
visionOSPoC exploitHIGH2026-02-11
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpected process crash.
CVEs:CVE-2026-20636
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
visionOSPoC exploitHIGH2026-02-11
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privi...
CVEs:CVE-2026-20671
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2026-02-11
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. Turning off "Load remote content in messages” may not apply to all mail previews.
CVEs:CVE-2026-20673
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
visionOSPoC exploitHIGH2026-02-11
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing maliciously crafted web content may ...
CVEs:CVE-2026-20635
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2026-02-11
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be able to capture a user's screen.
CVEs:CVE-2026-20622
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2026-02-11
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3. An app may be able to access protected user data.
CVEs:CVE-2026-28855
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
visionOSPoC exploitHIGH2026-02-11
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26....
CVEs:CVE-2026-20611
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2026-02-11
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to crash a system process.
CVEs:CVE-2026-20605
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
visionOSPoC exploitMEDIUM2026-02-11
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. Processing a mali...
CVEs:CVE-2026-20634
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2026-02-11
A path handling issue was addressed with improved logic. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to access user-sensitive data.
CVEs:CVE-2025-43417
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2026-02-11
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker may be able to discover a user’s deleted notes.
CVEs:CVE-2026-20682
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
visionOSPoC exploitHIGH2026-02-11
This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. Processing maliciously crafted web content may lead to an unexpecte...
CVEs:CVE-2026-20608
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
visionOSPoC exploitMEDIUM2026-02-11
This issue was addressed through improved state management. This issue is fixed in Safari 26.3, iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3. A website may be able to track users through Safari web extensions.
CVEs:CVE-2026-20676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
visionOSPoC exploitMEDIUM2026-02-11
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.
CVEs:CVE-2026-20625
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2026-02-11
This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user data.
CVEs:CVE-2026-20686
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2026-02-11
An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.
CVEs:CVE-2026-20624
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2026-02-11
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26. An app may be able to access sensitive user data.
CVEs:CVE-2025-43403
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2026-02-11
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26. An attacker with root privileges may be able to delete protected system files.
CVEs:CVE-2025-46310
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2026-02-11
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to iPhone may be able to take and view screenshots of sensitive data from the iPhone du...
CVEs:CVE-2026-20640
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2026-02-11
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
CVEs:CVE-2026-20662
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
visionOSPoC exploitMEDIUM2026-02-11
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A...
CVEs:CVE-2026-20653
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2026-02-11
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user inf...
CVEs:CVE-2026-20645
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2026-02-11
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
CVEs:CVE-2026-20661
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2026-02-11
A privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
CVEs:CVE-2026-20674
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2026-02-11
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3. A user with Live Caller ID app extensions turned off could have identifying information leaked to the extensions.
CVEs:CVE-2026-20638
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
visionOSPoC exploitMEDIUM2026-02-11
An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3, watchOS 26.3. An app may be able to acc...
CVEs:CVE-2026-20627
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSPoC exploitLOW2026-02-11
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to monitor keystrokes without user permission.
CVEs:CVE-2026-20601
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2026-02-11
The issue was addressed with improved handling of caches. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to cause a denial-of-service.
CVEs:CVE-2026-20602
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitLOW2026-02-11
An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person with physical access to an iOS device may be able to access photos from the lock screen.
CVEs:CVE-2026-20642
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
visionOSPoC exploitHIGH2026-02-11
A privacy issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able t...
CVEs:CVE-2026-20641
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| tvos |
affected |
apple |
— |
— |
| visionos |
affected |
apple |
— |
— |
| watchos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2026-02-11
This issue was addressed with improved data protection. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.
CVEs:CVE-2026-20647
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitHIGH2026-02-11
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to bypass certain Privacy preferences.
CVEs:CVE-2026-20606
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2026-02-11
A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.
CVEs:CVE-2026-20612
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
visionOSPoC exploitMEDIUM2026-02-11
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to cause unexpected sys...
CVEs:CVE-2026-20621
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2026-02-11
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.
CVEs:CVE-2026-20619
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2026-02-11
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Tahoe 26.3. An app with root privileges may be able to access private information.
CVEs:CVE-2026-20603
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2026-02-11
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app may be able to access user-sensitive data.
CVEs:CVE-2026-20618
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2026-02-11
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.
CVEs:CVE-2026-20669
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2026-02-11
A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Tahoe 26.3. A malicious app may be able to access notifications from other iCloud devices.
CVEs:CVE-2026-20648
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2026-02-11
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data.
CVEs:CVE-2026-20623
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2026-02-11
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user data.
CVEs:CVE-2026-20678
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2026-02-11
The issue was addressed with additional restrictions on the observability of app states. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. A sandboxed app may be ...
CVEs:CVE-2026-20680
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitLOW2026-02-11
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.3. A malicious app may be able to read sensitive location information.
CVEs:CVE-2026-20646
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2026-02-11
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.3. An app may be able to access protected user data.
CVEs:CVE-2026-20630
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitLOW2026-02-11
The issue was resolved by sanitizing logging. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to enumerate a user's installed apps.
CVEs:CVE-2026-20663
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
macOSPoC exploitHIGH2026-02-11
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Tahoe 26.3. An app may be able to access user-sensitive data.
CVEs:CVE-2026-20629
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitLOW2026-02-11
A logic issue was addressed with improved validation. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3. An app may be able to access a user's Safari history.
CVEs:CVE-2026-20656
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
| macos |
affected |
apple |
— |
— |
| safari |
affected |
apple |
— |
— |
macOSPoC exploitLOW2026-02-11
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26.3. An app may be able to access information about a user's contacts.
CVEs:CVE-2026-20681
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |
iPadOSPoC exploitMEDIUM2026-02-11
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
CVEs:CVE-2026-20655
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ipados |
affected |
apple |
— |
— |
| iphone_os |
affected |
apple |
— |
— |
macOSPoC exploitMEDIUM2026-02-11
An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.
CVEs:CVE-2026-20666
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| macos |
affected |
apple |
— |
— |