LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20700: Apple Multiple Buffer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 12, 2026
CVSS 7.8 · High⚠ Actively exploited (CISA KEV)
7.8
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 5, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20700 to its Known Exploited Vulnerabilities catalog on Feb 12, 2026, with a federal patch deadline of Mar 5, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.

This vulnerability affects multiple Apple operating systems and stems from a buffer overflow condition. An attacker who can write to memory may be able to run arbitrary code on affected devices. The issue is relevant for organizations that manage Apple devices because successful exploitation can lead to full system compromise.

How it works

The weakness is categorized as CWE-119, which describes improper restriction of operations within the bounds of a memory buffer. In this class of flaw, input or data handling exceeds the allocated memory region.

An attacker who already possesses the ability to write to memory can leverage the overflow to alter control flow and execute arbitrary code. The CISA summary notes this capability specifically for the listed Apple platforms; exact trigger conditions and prerequisites must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability is reported in Apple iOS, macOS, tvOS, watchOS, and visionOS. These platforms run on iPhones, iPads, Mac computers, Apple TV, Apple Watch, and Vision Pro devices in both consumer and enterprise environments.

How to remediate

Apply the update or mitigation instructions published by Apple for the affected platforms. The primary action is to install the vendor-supplied fix once it is available for each product.

If you can't patch immediately

Until the vendor update can be applied, follow the CISA required actions: implement mitigations described in the vendor instructions, adhere to BOD 22-01 guidance for any cloud services, or discontinue use of the affected product if no mitigations are feasible.

If your data may have been exposed

Buffer overflow vulnerabilities that permit arbitrary code execution have been used in past incidents to gain persistent access. Organizations should review device activity for signs of compromise and can run a free exposure scan of their email addresses to check against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
WeaknessCWE-119
CVSS base score7.8 (High)
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PublishedFeb 11, 2026
Added to CISA KEVFeb 12, 2026
Federal patch deadlineMar 5, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities