Description A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.
CVSS vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Exploitability: 2.2 | Impact: 6.0 Attack Vector: Network
Complexity: High
Privileges: None
User Interaction: None
Scope: Changed
Confidentiality: High
Integrity: High
Availability: High
Affected Packages7 packages Show 2 more packages
🔴 Vulnerability Details2 GHSA GHSA-qjq9-mpcc-f8cr: A race condition was addressed with improved handling of symbolic links ↗ 2026-02-12 ▶ CVEList CVE-2026-20677: A race condition was addressed with improved handling of symbolic links ↗ 2026-02-11 ▶
📋 Vendor Advisories5 Apple CVE-2026-20677: macOS Sonoma 14.8.4 ↗ 2026-02-11 ▶ Apple CVE-2026-20677: macOS Tahoe 26.3 ↗ 2026-02-11 ▶ Apple CVE-2026-20677: iOS 18.7.5 and iPadOS 18.7.5 ↗ 2026-02-11 ▶ Apple CVE-2026-20677: iOS 26.3 and iPadOS 26.3 ↗ 2026-02-11 ▶ Apple CVE-2026-20677: visionOS 26.3 ↗ 2026-02-11 ▶
🕵️ Threat Intelligence1 Wiz CVE-2026-20677 Impact, Exploitability, and Mitigation Steps | Wiz ↗ ▶