CVE-2026-20612
published 2026-02-11CVE-2026-20612: A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to…
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.13%
3.3th percentile
A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 14.8.4 | 14.8.4 |
| apple | macos | < 15.7.4 | 15.7.4 |
| apple | macos | < 26.3 | 26.3 |
| apple | macos | >= 14.0 < 14.8.4 | 14.8.4 |
| apple | macos | >= 15.0 < 15.7.4 | 15.7.4 |
| apple | macos | >= 26.0 < 26.3 | 26.3 |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_tahoe | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2026-20612: macOS Tahoe 26.3
vendor_apple·2026-02-11·CVSS 5.5
CVE-2026-20612 [MEDIUM] CVE-2026-20612: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20612
Component: Spotlight
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved checks.
Apple
CVE-2026-20612: macOS Sequoia 15.7.4
vendor_apple·2026-02-11·CVSS 5.5
CVE-2026-20612 [MEDIUM] CVE-2026-20612: macOS Sequoia 15.7.4
Apple Security Update: About the security content of macOS Sequoia 15.7.4
Product: macOS Sequoia
Version: 15.7.4
CVE: CVE-2026-20612
Component: Spotlight
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved checks.
Apple
CVE-2026-20612: macOS Sonoma 14.8.4
vendor_apple·2026-02-11·CVSS 5.5
CVE-2026-20612 [MEDIUM] CVE-2026-20612: macOS Sonoma 14.8.4
Apple Security Update: About the security content of macOS Sonoma 14.8.4
Product: macOS Sonoma
Version: 14.8.4
CVE: CVE-2026-20612
Component: Spotlight
Impact: An app may be able to access sensitive user data
Description: A privacy issue was addressed with improved checks.
GHSA
GHSA-25q2-mm9v-fcj8: A privacy issue was addressed with improved checks
ghsa_unreviewed·2026-02-12
CVE-2026-20612 [MEDIUM] CWE-200 GHSA-25q2-mm9v-fcj8: A privacy issue was addressed with improved checks
A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3, macOS Sonoma 14.8.4. An app may be able to access sensitive user data.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-20612 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20612 [HIGH] CVE-2026-20612 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20612 :
macOS vulnerability analysis and mitigation
A privacy issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An app may be able to access sensitive user data.
Source : NVD
## 5.5
Score
Published February 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
macOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Spotlight
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related macOS vulnerabilities:
CVE I
Bugzilla
CVE-2026-42015 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling
bugzilla·2026-05-07·CVSS 5.3
CVE-2026-42015 [MEDIUM] CVE-2026-42015 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling
CVE-2026-42015 gnutls: gnutls: Memory corruption due to off-by-one error in PKCS#12 bag handling
libgnutls: Fix off-by-one in PKCS#12 bag element bounds check
Appending to a PKCS#12 bag that already contained 32 elements
could write past the bag's internal array.
Reported by Zou Dikai.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2026:20611 https://access.redhat.com/errata/RHSA-2026:20611
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:20613 https://access.redhat.com/errata/RHSA-2026:20613
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:20612 https://access.redhat.com/errata/RHSA-2026:20612
2026-02-11
Published