CVE-2026-20700
published 2026-02-11CVE-2026-20700: A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS…
PriorityP182high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-03-05
Exploited in the wild
EPSS
1.32%
67.7th percentile
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_26.3_and_ipados | — | — |
| apple | ipados | < 26.3 | 26.3 |
| apple | iphone_os | < 26.3 | 26.3 |
| apple | macos | < 26.3 | 26.3 |
| apple | macos_tahoe | — | — |
| apple | tvos | < 26.3 | 26.3 |
| apple | tvos | — | — |
| apple | visionos | < 26.3 | 26.3 |
| apple | visionos | — | — |
| apple | watchos | < 26.3 | 26.3 |
| apple | watchos | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2026-20700 affects the CoreServices component on Apple platforms; detection should focus on anomalous app-level access to sensitive user data or unexpected environment variable manipulation by apps on iOS/iPadOS/macOS/tvOS/watchOS/visionOS. ↗
- →CVE-2026-20700 was exploited as part of a multi-CVE chain alongside CVE-2025-14174 and CVE-2025-43529; detections should consider correlating exploitation indicators across all three CVEs in the same incident timeline. ↗
- →The vulnerability was exploited in highly targeted attacks against specific individuals on iOS versions prior to iOS 26; threat hunting should prioritize devices running iOS before iOS 26 that have not been patched to iOS 18.7.5 or iOS 26.3. ↗
- →Google's Threat Analysis Group (TAG) discovered and reported CVE-2026-20700; TAG-attributed campaigns and associated infrastructure should be cross-referenced when hunting for exploitation of this vulnerability. ↗
- →The exploit primitive requires memory write capability as a precondition for arbitrary code execution; look for prior-stage memory write primitives or sandbox escapes on Apple devices as a precursor indicator. ↗
- ·Apple has not publicly disclosed technical exploitation details, payload samples, or attacker infrastructure for CVE-2026-20700; no hashes, domains, IPs, or signatures are available from the sources provided. ↗
- ·The vulnerability description differs between Apple's security bulletins (CoreServices / environment variable handling / sensitive data access) and the NVD/CISA description (memory corruption / buffer overflow / arbitrary code execution); defenders should treat both impact descriptions as potentially applicable to the same underlying flaw. ↗
- ·CISA's KEV remediation deadline was 2026-03-05 for FCEB agencies; patching to iOS 18.7.5 / iPadOS 18.7.5 / macOS Tahoe 26.3 / tvOS 26.3 / watchOS 26.3 / visionOS 26.3 is the only confirmed mitigation. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j5x8-2r52-c3ff: A memory corruption issue was addressed with improved state management
ghsa_unreviewed·2026-02-12·CVSS 8.8
CVE-2026-20700 [HIGH] CWE-119 GHSA-j5x8-2r52-c3ff: A memory corruption issue was addressed with improved state management
A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.
VulnCheck
Apple Multiple Buffer Overflow Vulnerability
vulncheck·2026·CVSS 7.8
CVE-2026-20700 [HIGH] CWE-119 Apple Multiple Buffer Overflow Vulnerability
Apple Multiple Buffer Overflow Vulnerability
Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code.
Affected: Apple Multiple Products
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://support.apple.com/en-us/126346; https://support.apple.com/en-us/126348; https://support.apple.com/en-us/126351; https://support.apple.com/en-us/126352; https://support.apple.com/e
CISA
Apple Multiple Buffer Overflow Vulnerability
cisa·2026-02-12·CVSS 7.8
CVE-2026-20700 [HIGH] CWE-119 Apple Multiple Buffer Overflow Vulnerability
Vulnerability: Apple Multiple Buffer Overflow Vulnerability
Affected: Apple Multiple Products
Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow an attacker with memory write the capability to execute arbitrary code.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://support.apple.com/en-us/126346 ; https://support.apple.com/en-us/126348 ; https://support.apple.com/en-us/126351 ; https://support.apple.com/en-us/126352 ; https://support.apple.com/en-us/126353 ; https://nvd.nist.gov/vuln/detail/CVE-2026-20700
Remediation Due Date: 2026-
Apple
CVE-2026-20700: watchOS 26.3
vendor_apple·2026-02-11·CVSS 7.8
CVE-2026-20700 [HIGH] CVE-2026-20700: watchOS 26.3
Apple Security Update: About the security content of watchOS 26.3
Product: watchOS
Version: 26.3
CVE: CVE-2026-20700
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation.
Apple
CVE-2026-20700: macOS Tahoe 26.3
vendor_apple·2026-02-11·CVSS 7.8
CVE-2026-20700 [HIGH] CVE-2026-20700: macOS Tahoe 26.3
Apple Security Update: About the security content of macOS Tahoe 26.3
Product: macOS Tahoe
Version: 26.3
CVE: CVE-2026-20700
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation.
Apple
CVE-2026-20700: iOS 26.3 and iPadOS 26.3
vendor_apple·2026-02-11·CVSS 7.8
CVE-2026-20700 [HIGH] CVE-2026-20700: iOS 26.3 and iPadOS 26.3
Apple Security Update: About the security content of iOS 26.3 and iPadOS 26.3
Product: iOS 26.3 and iPadOS
Version: 26.3
CVE: CVE-2026-20700
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation.
Apple
CVE-2026-20700: visionOS 26.3
vendor_apple·2026-02-11·CVSS 7.8
CVE-2026-20700 [HIGH] CVE-2026-20700: visionOS 26.3
Apple Security Update: About the security content of visionOS 26.3
Product: visionOS
Version: 26.3
CVE: CVE-2026-20700
Component: CoreServices
Impact: An app may be able to access sensitive user data
Description: An issue existed in the handling of environment variables. This issue was addressed with improved validation.
Apple
CVE-2026-20700: tvOS 26.3
vendor_apple·2026-02-11·CVSS 7.8
CVE-2026-20700 [HIGH] CVE-2026-20700: tvOS 26.3
Apple Security Update: About the security content of tvOS 26.3
Product: tvOS
Version: 26.3
CVE: CVE-2026-20700
Component: CoreServices
Impact: An app may be able to gain root privileges
Description: A race condition was addressed with improved state handling.
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
blogs_bleepingcomputer·2026-04-01·CVSS 8.8
CVE-2025-31277 [HIGH] Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
## Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
## Lawrence Abrams
In March, researchers at Lookout, iVerify, and Google Threat Intelligence revealed a new "DarkSword" exploit kit that targeted iPhones running iOS 18.4 through 18.7.
The six vulnerabilities used by the DarkSword exploit kit are tracked as CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
While iOS exploits have typically been used in highly targeted spyware campaigns, this iOS exploit kit was used much more widely, including by Turkish commercial surveillance vendor PARS Defense, a threat actor tracked as UNC6748, and a suspected Russian espionage group tracked as UNC6353.
In these attacks, GTIG observed three separate information-stealing mal
Bleepingcomputer
New DarkSword iOS exploit used in infostealer attack on iPhones
blogs_bleepingcomputer·2026-03-18·CVSS 8.8
CVE-2025-31277 [HIGH] New DarkSword iOS exploit used in infostealer attack on iPhones
## New DarkSword iOS exploit used in infostealer attack on iPhones
## Bill Toulas
iVerify's findings indicate that all flaws (sandbox escape, privilege escalation, remote code execution) exploited in this exploit chain are known or documented, and Apple has already addressed them in the latest iOS releases.
The DarkSword exploit kit uses six vulnerabilities tracked as CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
## DarkSword attacks
In a report today, Google Threat Intelligence Group (GTIG) says that DarkSword has been used since at least November 2025 by several threat actors, who deployed three separate malware families:
GHOSTBLADE, a dataminer in JavaScript that steals a swath of information, including crypto wallet data, syst
Mandiant
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
blogs_mandiant·2026-03-18
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
## The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
## Google Threat Intelligence Group
## Google Threat Intelligence
Visibility and context on the threats that matter most.
## Introduction
Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG has observed multiple commercial surveillance vendors and suspected state-sponsored actors utilizing DarkSword in distinct campaigns. These threat actors have deployed the exploit chain against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine.
DarkSword supports iOS vers
Bleepingcomputer
Apple patches older iPhones and iPads against Coruna exploits
blogs_bleepingcomputer·2026-03-12·CVSS 7.8
CVE-2023-41974 [HIGH] Apple patches older iPhones and iPads against Coruna exploits
## Apple patches older iPhones and iPads against Coruna exploits
## Sergiu Gatlan
Apple said the patches will fix iOS security issues targeted by multiple exploit chains, many used in zero-day attacks aiming to help attackers escalate permissions to Kernel privileges or gain remote code execution on vulnerable devices.
The list of vulnerabilities addressed by these backported security patches includes:
CVE-2023-41974: A Kernel use-after-free issue addressed with improved memory management
CVE-2024-23222: A WekKit type confusion issue addressed with improved checks
CVE-2023-43000: A WebKit use-after-free issue addressed with improved memory management
CVE-2023-43010: A WebKit issue was addressed with improved memory handling
The list of devices impacted by these vulnerabilities is a
Bleepingcomputer
Apple fixes zero-day flaw used in 'extremely sophisticated' attacks
blogs_bleepingcomputer·2026-02-11·CVSS 8.8
CVE-2025-14174 [HIGH] Apple fixes zero-day flaw used in 'extremely sophisticated' attacks
## Apple fixes zero-day flaw used in 'extremely sophisticated' attacks
## Lawrence Abrams
Apple says it is aware of reports that the flaw, along with the CVE-2025-14174 and CVE-2025-43529 flaws fixed in December , were exploited in the same incidents.
"An attacker with memory write capability may be able to execute arbitrary code," reads Apple's security bulletin .
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report."
Apple says Google's Threat Analysis Group discovered CVE-2026-20700. The company did not provide any further details about how the vulnerability was exploited.
Affected
Wiz
CVE-2026-20700 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-20700 [HIGH] CVE-2026-20700 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-20700 :
macOS vulnerability analysis and mitigation
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.
Source : NVD
## 7.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 7.8
Affected Technologies
macOS
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Recorded Future
February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
blogs_recorded_future·CVSS 7.7
[HIGH] February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
# February 2026 CVE Landscape:13 Critical Vulnerabilities Mark 43% Drop from January
February 2026 saw a 43% decrease in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 13 vulnerabilities requiring immediate remediation, down from 23 in January 2026. All 13 carried a ‘Very Critical’ Recorded Future Risk Score.
What security teams need to know:
- Microsoft dominates: Six of 13 vulnerabilities affected Microsoft products, accounting for 46% of February's findings; all were added to CISA's KEV catalog on the same day
- Supply-chain attack on Notepad++: Lotus Blossom, a suspected China state-sponsored threat actor, exploited CVE-2025-15556 to hijack Notepad++'s update channel and deliver a Cobalt Strike Beacon and the Chrysalis backdoor
- APT28 exploits MSHTML
2026-02-11
Published
2026-02-12
Added to CISA KEV
Exploited in the wild