
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20615 is a path traversal vulnerability (CWE-22) in Apple's CoreServices component that allows a malicious app to gain root privileges. It affects iOS and iPadOS (before 26.3), macOS Sonoma (before 14.8.4), macOS Tahoe (before 26.3), and visionOS (before 26.3). The vulnerability was disclosed and patched on February 11, 2026. It carries a CVSS v3.1 base score of 7.8 (High), reflecting local exploitation with low privileges required and high impact across confidentiality, integrity, and availability (Apple Advisory iOS/iPadOS, Apple Advisory macOS Tahoe, Apple Advisory macOS Sonoma, Apple Advisory visionOS).
The vulnerability stems from improper path handling in Apple's CoreServices framework, classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). An attacker with a low-privileged app can exploit insufficient validation of file system paths to traverse outside restricted directories and perform operations that escalate privileges to root. The attack vector is local, requires low privileges, and no user interaction, making it exploitable by any installed app on the affected device. Apple addressed the issue with improved path validation in the patched releases (Apple Advisory iOS/iPadOS, Apple Advisory macOS Tahoe).
Successful exploitation allows a malicious app to gain root privileges on the affected device, resulting in complete compromise of confidentiality, integrity, and availability. An attacker achieving root access could read, modify, or delete any file on the system, install persistent malware, disable security controls, and potentially pivot to other connected systems or services. The vulnerability affects a broad range of Apple devices including iPhones, iPads, Macs running Sonoma and Tahoe, and Apple Vision Pro (Apple Advisory iOS/iPadOS, Apple Advisory macOS Sonoma, Apple Advisory visionOS).
Apple has released patches addressing CVE-2026-20615 in the following updates: iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, and visionOS 26.3, all released February 11, 2026. Users and administrators should update affected devices to these versions immediately via Software Update. No configuration-based workarounds have been published; upgrading to the patched release is the only recommended remediation (Apple Advisory iOS/iPadOS, Apple Advisory macOS Tahoe, Apple Advisory macOS Sonoma, Apple Advisory visionOS).
The vulnerability was credited to Csaba Fitzl (@theevilbit) of Iru and Gergely Kalman (@gergely_kalman), both well-known Apple security researchers, indicating responsible disclosure. Coverage appeared across security news outlets and aggregators including CyberInsider, The Daily Tech Feed, and BeyondMachines shortly after Apple's February 11, 2026 release. The broader February 2026 Apple security update received attention due to the simultaneous patching of over 90 vulnerabilities across Apple platforms, including a separately disclosed actively exploited zero-day (CVE-2026-20700) in the same release cycle (Apple Advisory iOS/iPadOS, Apple Advisory macOS Tahoe).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."