CVE-2026-20675 PUBLISHED CVSS 5.5 MEDIUM

The issue was addressed with improved bounds checks. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. Processing a maliciously crafted image may lead to disclosure of user information.

EPSS 0.01% · 1.7th percentile

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.01%
1.7th percentile

Affected Products

VendorProductVersions
ApplevisionOSunspecified
applemacos14.0, 15.0, 26.0
ApplemacOSunspecified, unspecified, unspecified
applewatchos0
appleipados26.0, 0
appleiphone_os0, 26.0
AppleiOS and iPadOSunspecified, unspecified
appletvos0
applevisionos0
ApplewatchOSunspecified
AppletvOSunspecified

Timeline

References

Open in Interactive Console →