Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityendpoint-software-vulnerabilitywidely-deployed-product-advisory

Apple Zero-Day CVE-2026-20700 Patched Across iOS, macOS, and Other Platforms

Updated 3mo agoFirst seen Feb 12, 20263 sources

Apple released security updates for CVE-2026-20700, a zero-day in dyld (the Dynamic Link Editor) that can enable arbitrary code execution when an attacker already has a memory-write capability. Apple said it is aware the issue “may have been exploited” in extremely sophisticated, targeted attacks against specific individuals, and credited Google Threat Analysis Group (TAG) with discovery. Apple also linked the same incident reporting to two earlier vulnerabilities (CVE-2025-14174 and CVE-2025-43529) that were previously addressed.

The fixes were shipped across Apple’s ecosystem, including iOS/iPadOS, macOS (including macOS Tahoe), tvOS, watchOS, and visionOS; impacted device families include iPhone 11 and later and multiple iPad generations, as well as Macs running macOS Tahoe. Canadian Centre for Cyber Security guidance echoed Apple’s warning of potential exploitation and urged rapid patching (e.g., iOS/iPadOS 18.7.5 and 26.3 releases for newer OS lines). Other vendor advisories published in the same period (HPE, Chrome, Intel, Fortinet, Siemens, Dell, CISA ICS, IBM, Red Hat) are unrelated to the Apple zero-day and reflect routine multi-vendor patch activity rather than the specific exploitation event.

Share:
Apple Zero-Day CVE-2026-20700 Patched Across iOS, macOS, and Other Platforms
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 11, 20264mo ago

Canadian Centre for Cyber Security issues Apple advisory

The Canadian Centre for Cyber Security published advisory AV26-122 on February 11, 2026, summarizing Apple’s security updates and noting that CVE-2026-20700 may have been exploited in the wild. It urged users and administrators to review Apple’s guidance and apply the patches.

Apple releases broad February 2026 security updates

On February 11, 2026, Apple released security updates across iOS, iPadOS, macOS, tvOS, watchOS, and visionOS, fixing numerous vulnerabilities affecting components such as WebKit, Kernel, Foundation, CFNetwork, Bluetooth, Wi‑Fi, and multiple apps and frameworks. The updates included fixes for denial-of-service, memory corruption, data exposure, sandbox escape, and privilege-escalation issues, including CVE-2026-20700.

Apple says CVE-2026-20700 was used in targeted attacks

Apple stated it is aware of reports that CVE-2026-20700 may have been exploited in an 'extremely sophisticated' attack against specific targeted individuals on iOS versions prior to iOS 26. The company did not disclose technical details of the exploitation.

Google TAG discovers dyld zero-day CVE-2026-20700

Google’s Threat Analysis Group identified CVE-2026-20700, an arbitrary code execution flaw in Apple’s dyld component. Apple later credited TAG for the discovery in its February 2026 security updates.

Dec 1, 20257mo ago

Apple fixes two vulnerabilities later linked to same attack chain

Apple had previously patched CVE-2025-14174 and CVE-2025-43529 in December 2025. In its February 2026 advisories, Apple said CVE-2026-20700 was exploited in the same incidents as those two earlier flaws.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

81 LINKEDOpen in app
Vulnerabilities
71 linked
Apple dyld user-mode PAC bypass and memory corruptionOut-of-bounds access in Apple ImageIO media file processingMemory corruption in Apple WindowServer (macOS)Sensitive data exposure via logic issue in CoreServices (macOS Tahoe 26.2)Out-of-bounds write in Apple Model I/O USD file parsingUntitledSiri lock-screen authorization bypass via state management issue (macOS)Apple Multi-Touch bounds-checking issue leading to process crash via malicious HID device (CVE-2025-46305)WebKit denial-of-service in Apple Safari, iOS, iPadOS, macOS, visionOS, WebKitGTK, and WPE WebKitSensitive data exposure via insufficient log redaction in macOS System SettingsLocal Privilege Escalation to root in Apple CoreServices (race condition)Contacts log redaction privacy leak in macOS Tahoe (Contacts)Temporary file handling information disclosure in macOS Tahoe (Foundation)Out-of-bounds read in Apple GPU Drivers (macOS)Sensitive screenshot exposure during iPhone Mirroring in iOS/iPadOS (UI state management)Keystroke monitoring without user permission in macOS FoundationArbitrary File Write in Apple CFNetworkSensitive data exposure in macOS (fixed in macOS Tahoe 26.3)Path handling flaw in Apple Books backup restoreApple Live Captions lock screen information disclosurePrivacy preferences bypass in Apple UIKit (CVE-2026-20606)Out-of-bounds access in Apple CoreAudio media file processing (CVE-2026-20611)Denial-of-service in macOS WindowServer cache handlingCoreServices path-handling LPE to root (Apple platforms)Sensitive data exposure via temporary file handling in macOS Foundation (macOS Tahoe 26.3)Lock screen photo access via input validation issue in iOS/iPadOS PhotosSensitive data access via authorization/state management flaw in macOS Tahoe (fixed in 26.3)Sensitive data access via environment variable handling in Apple CoreServicesProtected system file deletion via state management flaw in macOS PackageKitSensitive User Data Access in Apple Sandbox ProfilesNotification privacy leak in macOS Tahoe (iCloud notifications)Sensitive data exposure via injection in AppleMobileFileIntegrity (macOS)Game Center Sensitive Information Disclosure via Insufficient Log RedactionAuthorization bypass in macOS Compression (state management)macOS Tahoe Permissions Issue Allowing Access to Protected User Data (CVE-2026-20630)Identifying information leak to Live Caller ID app extensions in iOS/iPadOS (Call History)Kernel denial-of-service in Apple operating systemsMail remote content setting bypass in message previews (Apple Mail)Sandbox bypass via symlink race condition in Apple Messages (Shortcuts)Information disclosure in Apple ImageIO via crafted image (bounds check issue)iOS/iPadOS VoiceOver lock-screen authorization bypass via state managementProtected user data access via permissions issue in macOS Foundation (macOS Tahoe < 26.3)WebKit process crash on malicious web contentInformation disclosure in iOS/iPadOS Screenshots allows discovery of deleted NotesSensitive data access via directory-path parsing in Apple ShortcutsSafari history access via logic/validation issue (Apple Safari/iOS/iPadOS/macOS)Safari Web Extensions User Tracking Privacy IssueSensitive data access via directory path parsing in AppleMobileFileIntegrityUntitledSensitive data access via path handling issue in macOS File BookmarkSensitive data exposure via Spotlight app-state observability (CVE-2026-20680)Root Privilege Escalation in macOS Remote ManagementProcess memory disclosure in Apple ImageIO via crafted image parsingSensitive data access via directory path parsing issue in macOS Admin FrameworkSandbox permissions issue leading to sandbox escape in Apple SandboxLock-screen information disclosure via inconsistent UI state management in iOS/iPadOS AccessibilityiOS/iPadOS LaunchServices logging sanitization flaw enabling installed-app enumerationmacOS Security package validation issue leading to root privilege escalation (macOS Tahoe 26.3)Traffic interception (MITM) via logic issue in Apple Kernel/libnetcoreLocal root privilege escalation in Setup Assistant via symlink handling (macOS Tahoe)DoS in Apple Bluetooth via crafted packets (privileged network position)Sensitive information redaction issue in macOS Notification Center (macOS Tahoe < 26.3)Remote DoS in Apple Security component (macOS Sequoia/Sonoma)Sensitive data exposure in Spotlight (macOS)WebKit process crash on malicious web contentInstalled-app enumeration privacy issue in Apple StoreKitLocked-device sensitive information disclosure in iOS/iPadOS AccessibilityKernel memory corruption in Apple Wi‑Fi (CVE-2026-20621)macOS Tahoe Logging Redaction Issue Leaking Location DataCoreMedia memory disclosure and denial-of-service via crafted fileSandbox escape in Apple libxpc (CVE-2026-20667)
Affected products
9 linked
TvosVisionosIpadosWatchosMacos SonomaIosMacos TahoeMacos SequoiaIos
Organizations
1 linked
Apple
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.