VDB
CVE-2026-20686
CVE-2026-20686
PUBLISHED
CVSS 5.300000190734863 MEDIUM
This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user data.
EPSS 0.09% · 25.1th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.09%
25.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | ipados | 0, 0 |
| Apple | iOS and iPadOS | 0, 0 |
| apple | iphone_os | 0, 0 |
Exploit Intelligence
- https://support.apple.com/en-us/126346 (circl)
- ios_v2_generated.go (github-poc)
- ios_v2_generated.go (github-poc)
- ios_v2_generated.go (github-poc)
- ios_v2_generated.go (github-poc)
- ios_v1_generated.go (github-poc)
- ios_v1_generated.go (github-poc)
- ios_v1_generated.go (github-poc)
- ios_v1_generated.go (github-poc)
Timeline
- Mar 25, 2026 EPSS Score
- Mar 25, 2026 Coalition ESS Score
- Mar 25, 2026 CVE Published
- Mar 29, 2026 Security Advisory
- Apr 2, 2026 CVE Updated
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score