Apple patched CoreGraphics zero-day CVE-2026-20700 after sophisticated targeted attacks on iOS devices.
Apple patched CVE-2026-20700, an out-of-bounds write in CoreGraphics reported by Meta Product Security. Processing a maliciously crafted file can lead to arbitrary code execution, and Apple said the issue may have been exploited in extremely sophisticated attacks against specific people on iOS versions before iOS 27. Updates cover iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 on recent iPhones, iPads, and Macs. The report calls it Apple's second in-the-wild zero-day of 2026, after a February dyld flaw it also labels CVE-2026-20700, and notes seven in-the-wild zero-days fixed in 2025.
CVE-2026-20700 is an out-of-bounds write in Apple CoreGraphics.
Apple says it was used in extremely sophisticated attacks on specific iOS users.
A malicious file can lead to arbitrary code execution.
Fixes are in iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, and Sequoia 15.8.1.
Meta Product Security reported the flaw; it is Apple's second 2026 in-the-wild zero-day.
Full article403 words · extracted from bleepingcomputer.com · click to collapse
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
Tracked as CVE-2026-20700, this flaw stems from an out-of-bounds write weakness discovered by Meta Product Security in CoreGraphics, a framework used for two-dimensional vector graphics, image rendering, and text drawing across iOS, macOS, iPadOS, watchOS, and tvOS.
Successful exploitation of out-of-bounds write vulnerabilities can let attackers crash a program, corrupt data, or, in the worst case, gain remote code execution by writing data outside the allocated memory buffer.
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27," it warned on Monday.
"Processing a maliciously crafted file may lead to arbitrary code execution. An out-of-bounds write issue was addressed with improved bounds checking."
The complete list of devices impacted by this zero-day is extensive, as it impacts both older and newer models, including:
iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
and Macs running macOS Sequoia 15.8.1 and Tahoe 26.7.1
While this flaw is likely exploited only in highly targeted attacks, it is strongly advised to install these security updates promptly to prevent potential ongoing attacks.
With this vulnerability, Apple has fixed two zero-days exploited in the wild since the start of the year. The other one, an arbitrary code execution vulnerability in dyld (the Dynamic Link Editor used by Apple operating systems) tracked as CVE-2026-20700 and also exploited in extremely sophisticated targeted attacks, was patched in February.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Out of Bounds Memory Access in Google Chromium ANGLE Affects Chrome, Edge, Opera
Google Chromium contains an out of bounds memory access vulnerability in ANGLE, the graphics translation layer that handles rendering APIs such as WebGL. A remote attacker can trigger the flaw by luring a user to open a crafted HTML page, causing the browser to access memory outside of allocated bounds. Successful exploitation may permit memory disclosure or corruption in the renderer process, although the available data does not fully characterize the impact. Any user of a Chromium-based browser is potentially affected, including users of Google Chrome, Microsoft Edge, and Opera, among other Chromium-derived browsers. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-12-12, indicating active exploitation, while no public proof-of-concept is known and no CVSS score has been assigned yet.
Do: Update all Chromium-based browsers (Google Chrome, Microsoft Edge, Opera, and derivatives) to the latest vendor-released versions and verify the installed browser build on managed endpoints, enabling automatic updates where possible. Because this flaw is in CISA KEV, apply vendor mitigations per vendor instructions or follow applicable BOD 22-01 guidance for cloud services, and prioritize patching internet-facing and high-risk user populations.
8.8
22%
KEV
Google Chromium (ANGLE component)
Google Chrome (Chromium-based)
Microsoft Edge (Chromium-based)
+1 more
massbillions of users across Chromium-based browsers (Chrome alone has roughly 3 billion+ users)
Use-After-Free Privilege Escalation in Apple iOS, iPadOS, macOS and Other Platforms
CVE-2025-24085 is a use-after-free memory corruption flaw (CWE-416) in multiple Apple operating systems that Apple addressed with improved memory management. It is triggered by a malicious application already running on a vulnerable device, which can exploit the flaw to elevate its privileges. An attacker who tricks a user into installing and running a malicious app could gain elevated rights beyond the app's sandbox. All users of unpatched iPhones, iPads, Macs, Apple TVs, Apple Vision Pro headsets, and Apple Watches are potentially affected, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-01-29. Apple has confirmed the issue was actively exploited against versions of iOS before iOS 17.2, indicating in-the-wild exploitation, though no public proof-of-concept is known.
Do: Update devices to iOS/iPadOS 18.3 (or iPadOS 17.7.6 on older devices), macOS Sequoia 15.3 / Sonoma 14.7.5 / Ventura 13.7.5, tvOS 18.3, visionOS 2.3, and watchOS 11.3 as soon as possible. Because Apple reports active exploitation against iOS versions before 17.2, treat any iPhone or iPad still below iOS 17.2 as at elevated risk and prioritize it for patching. Inventory Apple device fleets via MDM and confirm updated OS builds are deployed, given the CISA KEV listing and the ~18% 30-day EPSS score.
10.0
18%
KEV
Apple iPhone OS (iOS) versions prior to iOS 18.3 (actively exploited against iOS versions before iOS 17.2)
Incorrect Authorization in Apple iOS/iPadOS Lets Attackers Disable USB Restricted Mode
CVE-2025-24200 is an incorrect authorization flaw (CWE-863) in Apple iOS and iPadOS, caused by an authorization issue in state management that Apple resolved with improved state handling. An attacker with brief physical access to a locked device can exploit the flaw to disable USB Restricted Mode, the feature that locks down a locked iPhone or iPad's USB data port against accessories after a set period. This allows USB accessories, including data-extraction and attack peripherals, to communicate with the device while it remains locked, with a high confidentiality and integrity impact (CVSS 6.1, physical attack vector). Any iPhone or iPad user running a version prior to the applicable fixed release is affected, with fixes shipped in iOS 15.8.4, iOS 16.7.11, iOS 18.3.1, iPadOS 15.8.4, iPadOS 16.7.11, iPadOS 17.7.5, and iPadOS 18.3.1. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-12.
Do: Update iPhones to iOS 15.8.4, iOS 16.7.11, or iOS 18.3.1 and iPads to iPadOS 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable to each device's branch, checking Settings > General > Software Update for unmanaged devices. Because exploitation requires physical access, prioritize high-risk users (executives, journalists, government personnel), confirm no fleet devices remain on unpatched builds, and avoid untrusted USB accessories and charging ports until updated. CISA's KEV listing requires federal agencies to apply the vendor patch per the required action or discontinue use of the product.
WebKit Out-of-Bounds Write Sandbox Escape in Apple iOS, Safari, and macOS
CVE-2025-24201 is an out-of-bounds write (CWE-787) in WebKit, the web rendering engine used across Apple's platforms, which Apple addressed with improved bounds checks. It is triggered by processing maliciously crafted web content, meaning a victim only has to load attacker-controlled web content in Safari or in any app that renders web content. A successful attacker can break out of the Web Content sandbox and perform unauthorized actions, an impact CISA scores at CVSS 10.0 (critical, scope-changing). Affected users include anyone running vulnerable versions of iOS, iPadOS, macOS Sequoia, Safari, visionOS, or watchOS; Debian Linux is also listed in the CPE data because Debian ships WebKit in its webkit packages. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2 (this patch is a supplementary fix for that previously blocked attack, extended to older branches), and the CVE was added to CISA's KEV catalog on 2025-03-13.
Do: Apply the vendor fixes immediately: Safari 18.3.1; iOS/iPadOS 18.3.2 (or 17.7.6, 16.7.11, or 15.8.4 on devices that cannot run the newest release); macOS Sequoia 15.3.2; visionOS 2.3.2; watchOS 11.4; and updated Debian webkit packages per Debian advisories. Because the CVE is in CISA's KEV catalog (added 2025-03-13), US federal agencies must patch per BOD 22-01, and all defenders should prioritize fleets with high-risk or frequently targeted users. Given the 'extremely sophisticated' targeted exploitation against individuals on iOS before 17.2, check whether targeted or high-value users' devices show indicators of compromise and ensure they are not left on older branches.
Memory Corruption in Apple iOS, iPadOS, macOS Audio Processing Enables Code Execution
CVE-2025-31200 is a memory corruption flaw (CWE-119) in Apple's audio stream handling, fixed with improved bounds checking, that allows code execution when a device processes an audio stream in a maliciously crafted media file. An attacker who can deliver such a file to a vulnerable Apple device can gain arbitrary code execution with full confidentiality, integrity, and availability impact (CVSS 3.1: 9.8 critical, network vector). Affected products are iOS, iPadOS, macOS (Sequoia), tvOS, visionOS, and watchOS on versions released before the April 2025 fixes. Apple stated the issue was exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before 18.4.1, and CISA added it to the KEV on 2025-04-17; EPSS estimates a 19.7% (97th percentile) probability of exploitation within 30 days. Public analyses describe it chained with the WebKit flaw CVE-2025-31201, which Apple patched in the same emergency updates.
Do: Update all Apple devices immediately: iOS/iPadOS 18.4.1 or later, macOS Sequoia 15.4.1 or later, tvOS 18.4.1 or later, visionOS 2.4.1 or later, and watchOS 11.5 or later; the same updates also fix the related actively exploited WebKit zero-day CVE-2025-31201. The flaw is in CISA KEV (added 2025-04-17), so US federal agencies must apply the updates per BOD 22-01 or discontinue use. Verify installed OS versions in Settings > General > About (iOS/iPadOS) or About This Mac, and prioritize high-risk/targeted users for immediate patching and review.
Use-After-Free in Apple WebKit (Safari, iOS, macOS) Allows Arbitrary Code Execution
CVE-2025-43529 is a use-after-free (CWE-416) flaw in Apple's WebKit browser engine, fixed via improved memory management. It is triggered when a device processes maliciously crafted web content, and successful exploitation can lead to arbitrary code execution with network reachability and no privileges required (CVSS 3.1: 8.8, user interaction needed). It affects a broad range of Apple products: Safari, iPhone OS/iOS, iPadOS, macOS, tvOS, visionOS, and watchOS, with fixes delivered in Safari 26.2, iOS/iPadOS 18.7.3 and 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2. Apple reports the issue was exploited in an 'extremely sophisticated' targeted attack against specific individuals on iOS versions before iOS 26, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-12-15 (a companion CVE-2025-14174 was issued for the same report). No public proof-of-concept is known, and EPSS assigns an 8.9% probability of exploitation within 30 days (95th percentile).
Do: Update affected devices to Safari 26.2, iOS/iPadOS 26.2 (or iOS/iPadOS 18.7.3 on devices that remain on the iOS 18 branch), macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, and watchOS 26.2, prioritizing mobile users and high-risk targeted individuals. Federal agencies must remediate per CISA BOD 22-01 requirements since the CVE is in the KEV catalog (added 2025-12-15); also review the related CVE-2025-14174 addressed by the same updates. Check device fleet inventory for WebKit-exposed Apple hardware that cannot reach the fixed versions and confirm patches have been applied.
Exploited Memory Corruption Flaw in Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS
CVE-2026-20700 is a memory corruption (buffer overflow) issue in multiple Apple operating systems that Apple addressed through improved state management. The flaw requires a local attack vector: an attacker who already has some memory-write capability on the device — typically obtained via a chained exploit such as a browser or sandbox escape — can leverage this bug to execute arbitrary code. Attackers gain code execution with the privileges of the compromised component, with high impact on confidentiality, integrity, and availability per the CVSS 7.8 (High) score. All users of iPhone, iPad, Mac, Apple TV, Vision Pro, and Apple Watch running versions earlier than the 26.3 updates are affected. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 26, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-02-12; related CVEs CVE-2025-14174 and CVE-2025-43529 were issued from the same report.
Do: Update all Apple devices to iOS/iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, and watchOS 26.3 or later; the fix also addresses related CVE-2025-14174 and CVE-2025-43529 from the same report. Federal agencies must meet the KEV/BOD 22-01 deadline by patching per vendor instructions or discontinuing affected device use. Given the targeted, exploit-kit-driven attacks (e.g., DarkSword/Coruna tooling reported in the wild), prioritize updates for high-risk users such as executives, journalists, and activists, and verify fleet-wide OS versions rather than assuming patch compliance.
versions prior to iPadOS 18.3 and prior to iPadOS 17.7.6
Apple macOS Sequoia versions prior to 15.3
+5 more
mass≈1 billion+ devices (Apple's active installed base spans iOS, iPadOS, macOS, watchOS, tvOS, and visionOS)
KEV
Apple iOS (iPhone) Versions prior to the fixed releases in each branch: iOS < 15.8.4, iOS < 16.7.11, and iOS < 18.3.1
Apple iPadOS (iPad) Versions prior to the fixed releases in each branch: iPadOS < 15.8.4, iPadOS < 16.7.11, iPadOS < 17.7.5, and iPadOS < 18.3.1
mass≈1 billion+ devices (Apple's active installed base; every iPhone/iPad running a pre-patch iOS/iPadOS release at the time of disclosure)
KEV
Apple Safari Versions prior to 18.3.1; fixed in Safari 18.3.1
Apple iPhone OS (iOS) iOS 15.x, 16.x and 18.x prior to the fixes; fixed in iOS 15.8.4, iOS 16.7.11, and iOS 18.3.2 (the referenced in-the-wild attacks targeted iOS versions before 17
Apple iPadOS iPadOS 15.x, 16.x, 17.x and 18.x prior to the fixes; fixed in iPadOS 15.8.4, 16.7.11, 17.7.6, and 18.3.2
+4 more
mass≈2 billion+ active Apple devices (iPhone, iPad, Mac, Apple Watch and Vision Pro all ship the affected WebKit; Apple publicly reports an active installed base…
KEV
PoC ×2
Apple iOS (iPhone OS) versions prior to iOS 18.4.1 (fixed in iOS 18.4.1)
Apple iPadOS versions prior to iPadOS 18.4.1 (fixed in iPadOS 18.4.1)
Apple macOS macOS Sequoia versions prior to 15.4.1 (fixed in macOS Sequoia 15.4.1)
+3 more
masswell over 1 billion Apple devices (iOS/iPadOS/macOS active installed base; all devices on pre-18.4.1/15.4.1 OS versions at disclosure were affected)
KEV
Apple Safari
All versions prior to Safari 26.2
Apple iPhone OS (iOS) Versions prior to iOS 26.2 (legacy branch fixed in iOS 18.7.3)
Apple iPadOS Versions prior to iPadOS 26.2 (legacy branch fixed in iPadOS 18.7.3)
+4 more
masswell over 1 billion Apple devices/users across iPhone, iPad, Mac, Apple TV, Apple Watch and Vision Pro running pre-26.2 (or pre-18.7.3 legacy) software
KEV
Apple iOS (iPhone OS) all versions prior to iOS 26.3
Apple iPadOS all versions prior to iPadOS 26.3
Apple macOS (Tahoe) all versions prior to macOS Tahoe 26.3
+3 more
mass≈1.5–2 billion active Apple devices (Apple's publicly reported active install base), with a large share likely on pre-26.3 versions