CVE-2026-20700
Published Feb 11, 2026
Last updated 6 days ago
- Description
- A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.
- Source
- product-security@apple.com
- NVD status
- Analyzed
- Products
- ipados, iphone_os, macos, tvos, visionos, watchos
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Apple Multiple Buffer Overflow Vulnerability
- Exploit added on
- Feb 12, 2026
- Exploit action due
- Mar 5, 2026
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-119
- Hype score
- Not currently trending
🚨 Russian APT Star Blizzard deploys DarkSword iOS exploit kit targeting 18.4-18.7. Full-chain: CVE-2025-31277 (JSCore RCE) → CVE-2026-20700 (PAC bypass) → CVE-2025-43520 (kernel privesc). GHOSTKNIFE backdoor exfils in minutes. Update to iOS 26.3+ now. #infosec
@psyciclabs
30 Mar 2026
181 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
TRC analysis shows the leaked DarkSword framework exploits zero-click iOS vulnerabilities (CVE-2025-31277, CVE-2026-20700) to establish remote device control. Attackers pivot across apps and data repositories to exfiltrate messages, account details, and location history. #ZeroDay
@aviatrixtrc
25 Mar 2026
166 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
"DarkSword" exploit chain, live since Nov 2025, linked 6 flaws: JavaScriptCore (CVE-2025-31277, CVE-2025-43529), dyld PAC bypass (CVE-2026-20700), WebContent sandbox escape (CVE-2025-14174). #cybersecurity
@bigmacd16684
23 Mar 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Google’s DarkSword disclosure details a sophisticated JavaScript-based exploit kit weaponizing multiple zero-days (including CVE-2026-20700 and CVE-2025-14174) to chain browser and kernel bugs and seize full control of iOS 18.x devices. Once active, the payload rapidly http
@Cryip_co
21 Mar 2026
5 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
📌 استغلال جهات تهديد متعددة لحزمة استغلال iOS "DarkSword" التي تستهدف ست ثغرات تستغل جهات تهديد متعددة بشكل نشط حزمة استغلال iOS متطورة تُعرف باسم "DarkSword"، والتي
@MisbarSec
20 Mar 2026
273 Impressions
0 Retweets
2 Likes
1 Bookmark
0 Replies
0 Quotes
DarkSword: second iOS exploit kit in a month. 6 flaws, 3 zero-days (CVE-2026-20700, CVE-2025-43529, CVE-2025-14174), full device takeover. Targets iOS 18.4-18.7. Russian group UNC6353 deploying it in Ukraine. Keep iOS updated. https://t.co/i2p7J4bmxA #infosec
@CybrPulse
20 Mar 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2023-20198 2 - CVE-2023-50428 3 - CVE-2026-0757 4 - CVE-2024-23225 5 - CVE-2026-20700 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
7 Mar 2026
158 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2026-2441 2 - CVE-2026-20700 3 - CVE-2026-2003 4 - CVE-2025-21042 5 - CVE-2025-59536 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
26 Feb 2026
182 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2026-20700 2 - CVE-2025-1234 3 - CVE-2026-21513 4 - CVE-2026-21241 5 - CVE-2025-5959 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
25 Feb 2026
245 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
The @CISAgov added 4 exploited bugs to KEV: SolarWinds WHD (CVE-2025-40536, 9.8), MS ConfigMgr SQLi→RCE (CVE-2024-43468, 9.8), Apple (CVE-2026-20700), Notepad++ (CVE-2025-15556). Patch fast. #cybersecurity #CISO #infosec #ITsecurity https://t.co/zHY8g3q1Ph
@SCMagazine
18 Feb 2026
265 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Vulnerabilidades en productos Apple ❗ CVE-2026-20700 ❗ CVE-2026-20628 ❗ CVE-2025-14174 ➡️ Más info: https://t.co/FopfG5Yavd https://t.co/tb0M4Lx0zO
@CERTpy
17 Feb 2026
87 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
The @CISAgov added 4 exploited bugs to KEV: SolarWinds WHD (CVE-2025-40536, 9.8), MS ConfigMgr SQLi→RCE (CVE-2024-43468, 9.8), Apple (CVE-2026-20700), Notepad++ (CVE-2025-15556). Patch fast. #cybersecurity #CISO #infosec #ITsecurity https://t.co/zHY8g3q1Ph
@SCMagazine
16 Feb 2026
1410 Impressions
2 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
The @CISAgov added 4 exploited bugs to KEV: SolarWinds WHD (CVE-2025-40536, 9.8), MS ConfigMgr SQLi→RCE (CVE-2024-43468, 9.8), Apple (CVE-2026-20700), Notepad++ (CVE-2025-15556). Patch fast. #cybersecurity #CISO #infosec #ITsecurity https://t.co/zHY8g3q1Ph
@SCMagazine
15 Feb 2026
369 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
The @CISAgov added 4 exploited bugs to KEV: SolarWinds WHD (CVE-2025-40536, 9.8), MS ConfigMgr SQLi→RCE (CVE-2024-43468, 9.8), Apple (CVE-2026-20700), Notepad++ (CVE-2025-15556). Patch fast. #cybersecurity #CISO #infosec #ITsecurity https://t.co/zHY8g3q1Ph
@SCMagazine
14 Feb 2026
309 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 CISA adds exploited SolarWinds, Notepad++, Apple, and Microsoft ConfigMgr flaws to KEV — patch-now priority CISA added four in-the-wild exploited CVEs (SolarWinds Web Help Desk bypass CVE-2025-40536, Notepad++ WinGUp update integrity CVE-2025-15556, Apple dyld CVE-2026-207
@ThreatSynop
13 Feb 2026
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の追加。Microsoft Configuration ManagerのCVE-2024-43468、Notepad++のCVE-2025-15556、SolarWinds Web Help DeskのCVE-2025-40536、Apple複数製品
@__kokumoto
12 Feb 2026
841 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🛡️ We added Microsoft vulnerability CVE-2024-43468, Notepad++ vulnerability CVE-2025-15556, SolarWinds vulnerability CVE 2025-40536, & Apple vulnerability CVE-2026-20700 to our KEV Catalog. Apply mitigations to protect your org from cyberattacks. https://t.co/myxOwap1Tf
@CISACyber
12 Feb 2026
6154 Impressions
33 Retweets
84 Likes
6 Bookmarks
1 Reply
3 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "73ED2212-C513-4BE8-8EDB-40DF4323558E",
"versionEndExcluding": "26.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "DEC63AFD-9C97-45CD-80CF-CC60DF064838",
"versionEndExcluding": "26.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E1EEEE88-5ADA-4C55-9C7C-397E904408DD",
"versionEndExcluding": "26.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:tvos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "60137BD4-65B6-4962-B1E5-5F4EE279489B",
"versionEndExcluding": "26.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "388EDB3F-A14E-4922-B88A-F1CB6DE50A2A",
"versionEndExcluding": "26.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F406F3D2-0AF3-4F83-A123-2AC07B3B094E",
"versionEndExcluding": "26.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]