cbcvebase.
CVE-2026-20700
published 2026-02-11

CVE-2026-20700: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS…

PriorityP182high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-03-05
Exploited in the wild
EPSS
1.32%
67.7th percentile
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.

Affected

11 ranges
VendorProductVersion rangeFixed in
appleios_26.3_and_ipados
appleipados< 26.326.3
appleiphone_os< 26.326.3
applemacos< 26.326.3
applemacos_tahoe
appletvos< 26.326.3
appletvos
applevisionos< 26.326.3
applevisionos
applewatchos< 26.326.3
applewatchos

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2026-20700 affects the CoreServices component on Apple platforms; detection should focus on anomalous app-level access to sensitive user data or unexpected environment variable manipulation by apps on iOS/iPadOS/macOS/tvOS/watchOS/visionOS.
  • CVE-2026-20700 was exploited as part of a multi-CVE chain alongside CVE-2025-14174 and CVE-2025-43529; detections should consider correlating exploitation indicators across all three CVEs in the same incident timeline.
  • The vulnerability was exploited in highly targeted attacks against specific individuals on iOS versions prior to iOS 26; threat hunting should prioritize devices running iOS before iOS 26 that have not been patched to iOS 18.7.5 or iOS 26.3.
  • Google's Threat Analysis Group (TAG) discovered and reported CVE-2026-20700; TAG-attributed campaigns and associated infrastructure should be cross-referenced when hunting for exploitation of this vulnerability.
  • The exploit primitive requires memory write capability as a precondition for arbitrary code execution; look for prior-stage memory write primitives or sandbox escapes on Apple devices as a precursor indicator.
  • ·Apple has not publicly disclosed technical exploitation details, payload samples, or attacker infrastructure for CVE-2026-20700; no hashes, domains, IPs, or signatures are available from the sources provided.
  • ·The vulnerability description differs between Apple's security bulletins (CoreServices / environment variable handling / sensitive data access) and the NVD/CISA description (memory corruption / buffer overflow / arbitrary code execution); defenders should treat both impact descriptions as potentially applicable to the same underlying flaw.
  • ·CISA's KEV remediation deadline was 2026-03-05 for FCEB agencies; patching to iOS 18.7.5 / iPadOS 18.7.5 / macOS Tahoe 26.3 / tvOS 26.3 / watchOS 26.3 / visionOS 26.3 is the only confirmed mitigation.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.