CVE-2026-20615
macOS vulnerability analysis and mitigation

Overview

CVE-2026-20615 is a path traversal vulnerability (CWE-22) in Apple's CoreServices component that allows a malicious app to gain root privileges. It affects iOS and iPadOS (before 26.3), macOS Sonoma (before 14.8.4), macOS Tahoe (before 26.3), and visionOS (before 26.3). The vulnerability was disclosed and patched on February 11, 2026. It carries a CVSS v3.1 base score of 7.8 (High), reflecting local exploitation with low privileges required and high impact across confidentiality, integrity, and availability (Apple Advisory iOS/iPadOS, Apple Advisory macOS Tahoe, Apple Advisory macOS Sonoma, Apple Advisory visionOS).

Technical details

The vulnerability stems from improper path handling in Apple's CoreServices framework, classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). An attacker with a low-privileged app can exploit insufficient validation of file system paths to traverse outside restricted directories and perform operations that escalate privileges to root. The attack vector is local, requires low privileges, and no user interaction, making it exploitable by any installed app on the affected device. Apple addressed the issue with improved path validation in the patched releases (Apple Advisory iOS/iPadOS, Apple Advisory macOS Tahoe).

Impact

Successful exploitation allows a malicious app to gain root privileges on the affected device, resulting in complete compromise of confidentiality, integrity, and availability. An attacker achieving root access could read, modify, or delete any file on the system, install persistent malware, disable security controls, and potentially pivot to other connected systems or services. The vulnerability affects a broad range of Apple devices including iPhones, iPads, Macs running Sonoma and Tahoe, and Apple Vision Pro (Apple Advisory iOS/iPadOS, Apple Advisory macOS Sonoma, Apple Advisory visionOS).

Mitigation and workarounds

Apple has released patches addressing CVE-2026-20615 in the following updates: iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, and visionOS 26.3, all released February 11, 2026. Users and administrators should update affected devices to these versions immediately via Software Update. No configuration-based workarounds have been published; upgrading to the patched release is the only recommended remediation (Apple Advisory iOS/iPadOS, Apple Advisory macOS Tahoe, Apple Advisory macOS Sonoma, Apple Advisory visionOS).

Community reactions

The vulnerability was credited to Csaba Fitzl (@theevilbit) of Iru and Gergely Kalman (@gergely_kalman), both well-known Apple security researchers, indicating responsible disclosure. Coverage appeared across security news outlets and aggregators including CyberInsider, The Daily Tech Feed, and BeyondMachines shortly after Apple's February 11, 2026 release. The broader February 2026 Apple security update received attention due to the simultaneous patching of over 90 vulnerabilities across Apple platforms, including a separately disclosed actively exploited zero-day (CVE-2026-20700) in the same release cycle (Apple Advisory iOS/iPadOS, Apple Advisory macOS Tahoe).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management