CVE-2026-20639
published 2026-03-25CVE-2026-20639: An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.60%
44.7th percentile
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3. Processing a maliciously crafted string may lead to heap corruption.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 14.8.5 | 14.8.5 |
| apple | macos | < 15.7.5 | 15.7.5 |
| apple | macos | < 26.3 | 26.3 |
| apple | macos | >= 14.0 < 14.8.5 | 14.8.5 |
| apple | macos | >= 15.0 < 15.7.5 | 15.7.5 |
| apple | macos | >= 26.0 < 26.3 | 26.3 |
| apple | macos_tahoe | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7gg2-3r7f-v522: An integer overflow was addressed with improved input validation
ghsa_unreviewed·2026-03-25
CVE-2026-20639 [HIGH] CWE-190 GHSA-7gg2-3r7f-v522: An integer overflow was addressed with improved input validation
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3. Processing a maliciously crafted string may lead to heap corruption.
Apple
CVE-2026-20639: macOS Tahoe 26.3
vendor_apple·2026-02-11·CVSS 7.5
CVE-2026-20639 [HIGH] CVE-2026-20639: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20639
Component: CFNetwork
Impact: A remote user may be able to write arbitrary files
Description: A path handling issue was addressed with improved logic.
No detection rules found.
No public exploits indexed.
2026-03-25
Published