Apple Zero-Day CVE-2026-20700 Patched Across iOS, macOS, and Other Platforms
Apple released security updates for CVE-2026-20700, a zero-day in dyld (the Dynamic Link Editor) that can enable arbitrary code execution when an attacker already has a memory-write capability. Apple said it is aware the issue “may have been exploited” in extremely sophisticated, targeted attacks against specific individuals, and credited Google Threat Analysis Group (TAG) with discovery. Apple also linked the same incident reporting to two earlier vulnerabilities (CVE-2025-14174 and CVE-2025-43529) that were previously addressed.
The fixes were shipped across Apple’s ecosystem, including iOS/iPadOS, macOS (including macOS Tahoe), tvOS, watchOS, and visionOS; impacted device families include iPhone 11 and later and multiple iPad generations, as well as Macs running macOS Tahoe. Canadian Centre for Cyber Security guidance echoed Apple’s warning of potential exploitation and urged rapid patching (e.g., iOS/iPadOS 18.7.5 and 26.3 releases for newer OS lines). Other vendor advisories published in the same period (HPE, Chrome, Intel, Fortinet, Siemens, Dell, CISA ICS, IBM, Red Hat) are unrelated to the Apple zero-day and reflect routine multi-vendor patch activity rather than the specific exploitation event.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
Canadian Centre for Cyber Security issues Apple advisory
The Canadian Centre for Cyber Security published advisory AV26-122 on February 11, 2026, summarizing Apple’s security updates and noting that CVE-2026-20700 may have been exploited in the wild. It urged users and administrators to review Apple’s guidance and apply the patches.
Apple releases broad February 2026 security updates
On February 11, 2026, Apple released security updates across iOS, iPadOS, macOS, tvOS, watchOS, and visionOS, fixing numerous vulnerabilities affecting components such as WebKit, Kernel, Foundation, CFNetwork, Bluetooth, Wi‑Fi, and multiple apps and frameworks. The updates included fixes for denial-of-service, memory corruption, data exposure, sandbox escape, and privilege-escalation issues, including CVE-2026-20700.
Apple says CVE-2026-20700 was used in targeted attacks
Apple stated it is aware of reports that CVE-2026-20700 may have been exploited in an 'extremely sophisticated' attack against specific targeted individuals on iOS versions prior to iOS 26. The company did not disclose technical details of the exploitation.
Google TAG discovers dyld zero-day CVE-2026-20700
Google’s Threat Analysis Group identified CVE-2026-20700, an arbitrary code execution flaw in Apple’s dyld component. Apple later credited TAG for the discovery in its February 2026 security updates.
Apple fixes two vulnerabilities later linked to same attack chain
Apple had previously patched CVE-2025-14174 and CVE-2025-43529 in December 2025. In its February 2026 advisories, Apple said CVE-2026-20700 was exploited in the same incidents as those two earlier flaws.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
Apple security advisory (AV26-122) - Canadian Centre for Cyber Security
cyber.gc.ca
Open sourceApple fixes zero-day flaw used in 'extremely sophisticated' attacks
bleepingcomputer.com
Open sourceApple Patches Everything: February 2026 - SANS ISC
isc.sans.edu
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


