Junglewise Threat Intelligence

CVE-2026-20652: Apple and Red Hat Multiple Products Buffer Overflow denial of service

CVE-2026-20652 · Severity: high · CVSS 7.5 · Published 2026-02-11

Technologies: Apple macOS, Apple Safari, Apple Visionos, Apple iPadOS, Red Hat Enterprise Linux. Vendors: Apple, Red Hat.

Executive brief

A memory handling vulnerability has been identified in several Apple operating systems and the Safari web browser, as well as certain Red Hat Enterprise Linux configurations. A remote attacker could exploit this flaw to cause a denial-of-service, potentially crashing the affected device or application and disrupting operations. Users should update to the latest software versions to mitigate this risk.

Technical details

A vulnerability classified as uncontrolled resource consumption (CWE-400) and classic buffer overflow (CWE-120) exists in multiple Apple operating systems and Red Hat Enterprise Linux. The issue stems from improper memory handling, which can be triggered by a remote attacker without prior authentication or user interaction. Successful exploitation allows the attacker to cause a denial-of-service (DoS) condition. Apple addressed the issue in Safari 26.3, iOS/iPadOS 18.7.5 and 26.3, macOS Tahoe 26.3, and visionOS 26.3 by improving memory handling. Red Hat has also released various security advisories (RHSAs) to address the flaw in affected Linux distributions.

Affected products

  • Apple iOS Before 18.7.5, 26.3
  • Apple iPadOS Before 18.7.5, 26.3
  • Apple macOS Tahoe Before 26.3
  • Apple Safari Before 26.3
  • Apple visionOS Before 26.3
  • Red Hat Enterprise Linux 7, 8, 9

Timeline

  • 2026-02-11: advisory: Initial NVD publication date
  • 2026-06-29: other: Red Hat enrichment data added to CVE record

References

Related threats