Apple Fixes Zero-Day Vulnerability CVE-2026-20700

2026-02-12T024706.485-0500data

Apple Releases Software Updates to Address Zero-Day Vulnerability

Apple has released a series of software updates to address a zero-day vulnerability that has been actively exploited in targeted cyber attacks.

Vulnerability Details

The flaw, identified as CVE-2026-20700, is a memory corruption issue in the Dynamic Link Editor (dyld) component of Apple’s operating systems. Successful exploitation of the vulnerability could allow an attacker to execute arbitrary code on affected devices.

According to Apple, the vulnerability has been exploited in sophisticated attacks against specific individuals using older versions of iOS. Google’s Threat Analysis Group (TAG) is credited with discovering and reporting the bug.

Related Vulnerabilities

Apple has also acknowledged that the vulnerability may have been exploited in conjunction with two other flaws, CVE-2025-14174 and CVE-2025-43529, which were addressed in December 2025.

CVE-2025-14174 is an out-of-bounds memory access vulnerability in the Metal renderer component of ANGLE, a high-performance graphics and compute API developed by Apple. CVE-2025-43529 is a use-after-free vulnerability in WebKit that can lead to arbitrary code execution when processing maliciously crafted web content.

Affected Devices and Updates

The software updates, which are available for various Apple devices and operating systems, include iOS 26.3, iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3, and visionOS 26.3. Additionally, Apple has released updates to resolve various vulnerabilities in older versions of iOS, iPadOS, macOS, and Safari.

The affected devices and operating systems include iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. Macs running macOS Tahoe, Apple TV HD and Apple TV 4K (all models), Apple Watch Series 6 and later, and Apple Vision Pro (all models) are also affected.

Additional Updates

Apple has released updates to resolve various vulnerabilities in older versions of iOS, iPadOS, macOS, and Safari, including iOS 18.7.5 and iPadOS 18.7.5 for iPhone XS, iPhone XS Max, iPhone XR, and iPad 7th generation. macOS Sequoia 15.7.4 and macOS Sonoma 14.8.4 are also available for Macs running the respective operating systems. Safari 26.3 is available for Macs running macOS Sonoma and macOS Sequoia.

Recommendation

The updates are designed to address the zero-day vulnerability and prevent further exploitation. Users are advised to apply the updates as soon as possible to ensure the security of their devices.


Blog Image

About Author

en_USEnglish