CVE-2026-20694 PUBLISHED CVSS 5.5 MEDIUM

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Sonoma 14.8.5, macOS Tahoe 26.3, macOS Tahoe 26.4. An app may be able to access user-sensitive data.

EPSS 0.02% · 6.5th percentile

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.02%
6.5th percentile

Affected Products

VendorProductVersions
appleipados0
ApplemacOS0, 0, 0
applemacos26.0, 14.0, 15.0
appleiphone_os0
AppleiOS and iPadOS0

Timeline

References

Open in Interactive Console →