Junglewise Threat Intelligence

CVE-2026-20657: Apple multiple operating systems buffer overflow via file parsing

CVE-2026-20657 · Severity: medium · CVSS 6.5 · Published 2026-03-25

Technologies: Apple macOS Tahoe, Apple Visionos, Apple iPadOS. Vendors: Apple.

Executive brief

A memory handling vulnerability exists in several Apple operating systems, including iOS, macOS, and visionOS. If a user opens a specially crafted malicious file, it could cause the application to crash or terminate unexpectedly. This primarily impacts the reliability and availability of apps on the affected device.

Technical details

A buffer overflow vulnerability (CWE-119) exists in multiple Apple operating systems due to improper memory handling during file parsing. The issue can be triggered when a system or application processes a maliciously crafted file, potentially leading to an out-of-bounds read or write and subsequent process termination (Denial of Service). The vulnerability was addressed by improving memory handling and bounds checking across affected components. Exploitation requires a user to open or process the malicious file (User Interaction). Patches are available in iOS 18.7.7, iOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, and visionOS 26.4.

Affected products

  • Apple iOS before 18.7.7, before 26.4
  • Apple iPadOS before 18.7.7, before 26.4
  • Apple macOS Sequoia before 15.7.5
  • Apple macOS Sonoma before 14.8.5
  • Apple macOS Tahoe before 26.4
  • Apple visionOS before 26.4

Timeline

  • 2026-03-24: patched: Initial patches released for various Apple platforms.
  • 2026-03-25: disclosed: NVD publication date.

References

Related threats