CVE-2026-20688 PUBLISHED CVSS 9.300000190734863 CRITICAL

A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. An app may be able to break out of its sandbox.

EPSS 0.02% · 4.5th percentile

Risk Scores

CVSS v3.1
9.300000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.02%
4.5th percentile

Affected Products

VendorProductVersions
ApplemacOS0, 0, 0
appleipados0
appleiphone_os0
applemacos26.0, 15.0, 14.0
ApplevisionOS0
applevisionos0
AppleiOS and iPadOS0

Timeline

References

Open in Interactive Console →