CVE-2026-20642
published 2026-02-11CVE-2026-20642: An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person with physical access to an iOS device may be able to access…
PriorityP46low2.4CVSS 3.1
AVPACLPRNUINSUCLINAN
EPSS
0.14%
3.5th percentile
An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person with physical access to an iOS device may be able to access photos from the lock screen.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_26.3_and_ipados | — | — |
| apple | ios_and_ipados | < 26.3 | 26.3 |
| apple | ipados | < 26.3 | 26.3 |
| apple | iphone_os | < 26.3 | 26.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2026-20642: iOS 26.3 and iPadOS 26.3
vendor_apple·2026-02-11·CVSS 2.4
CVE-2026-20642 [LOW] CVE-2026-20642: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20642
Component: Photos
Impact: A person with physical access to an iOS device may be able to access photos from the lock screen
Description: An input validation issue was addressed.
GHSA
GHSA-6jg9-x4w8-gj7j: An input validation issue was addressed
ghsa_unreviewed·2026-02-12
CVE-2026-20642 [LOW] CWE-284 GHSA-6jg9-x4w8-gj7j: An input validation issue was addressed
An input validation issue was addressed. This issue is fixed in iOS 26.3 and iPadOS 26.3. A person with physical access to an iOS device may be able to access photos from the lock screen.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-02-11
Published