Junglewise Threat Intelligence

CVE-2026-20615: Apple CoreServices path handling privilege escalation

CVE-2026-20615 · Severity: high · CVSS 7.8 · Published 2026-02-11

Technologies: Apple Visionos, Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

CoreServices is a core iOS and macOS component responsible for fundamental system operations. A flaw in how it validates file paths could allow an installed application to gain root-level privileges on affected devices, potentially enabling full system compromise and access to all user data.

Technical details

CVE-2026-20615 is a path handling vulnerability in CoreServices that was addressed through improved validation logic. The flaw allows an attacker with code execution in an app context to escalate privileges to root. The attack is local (requires an installed or running app) and does not require network access or physical device access. An attacker can exploit this vulnerability to achieve complete system compromise, bypass security boundaries, and access all protected user data and system resources. The vulnerability has been patched in iOS 26.3, iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, and visionOS 26.3.

Affected products

  • Apple iOS before 26.3
  • Apple iPadOS before 26.3
  • Apple macOS Sequoia before 15.7.4
  • Apple macOS Sonoma before 14.8.4
  • Apple macOS Tahoe before 26.3
  • Apple visionOS before 26.3

Timeline

  • 2026-02-11: disclosed
  • 2026-02-11: patched

References

Related threats