Junglewise Threat Intelligence

CVE-2026-20627: Apple CoreServices environment variable handling privilege escalation

CVE-2026-20627 · Severity: medium · CVSS 5.5 · Published 2026-02-11

Technologies: Apple watchOS, Apple Visionos, Apple macOS Sonoma, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's CoreServices component on iOS, iPadOS, and macOS contains a vulnerability in how it handles environment variables. An attacker can exploit this flaw through a malicious app to access sensitive user data or potentially gain elevated privileges. This could allow unauthorized access to personal information or system-level compromise on affected Apple devices.

Technical details

CVE-2026-20627 is an environment variable handling vulnerability in Apple's CoreServices framework affecting iOS, iPadOS, and macOS. The root cause involves improper validation of environment variables, allowing a local application to read or manipulate sensitive system state. An attacker must have local code execution (app running on the device) but does not require elevated privileges to trigger the vulnerability. The fix involves improved validation of environment variables to prevent unauthorized access to sensitive data. Patches are available in iOS 26.3, iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3, and watchOS 26.3.

Affected products

  • Apple iOS before 26.3
  • Apple iPadOS before 26.3
  • Apple macOS Sequoia before 15.7.4
  • Apple macOS Sonoma before 14.8.4
  • Apple macOS Tahoe before 26.3
  • Apple visionOS before 26.3
  • Apple watchOS before 26.3

Timeline

  • 2026-02-11: disclosed
  • 2026-02-11: patched: iOS 26.3, iPadOS 26.3, macOS Tahoe 26.3, visionOS 26.3, watchOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4

References

Related threats