
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20626 is a kernel-level privilege escalation vulnerability in Apple operating systems that allows a malicious app to gain root privileges. It was disclosed and patched on February 11, 2026, affecting iOS and iPadOS before 26.3, macOS Sequoia before 15.7.4, macOS Tahoe before 26.3, and visionOS before 26.3. The vulnerability was discovered by Keisuke Hosoda and carries a CVSS v3.1 base score of 7.8 (High) (Apple iOS/iPadOS Advisory, Apple macOS Tahoe Advisory, Apple macOS Sequoia Advisory).
The vulnerability is classified as CWE-862 (Missing Authorization) and resides in the kernel component of affected Apple platforms. Apple's advisory states the issue was addressed with "improved checks," indicating that insufficient authorization validation in a kernel code path allowed a low-privileged local app to escalate to root. The attack vector is local, requires low privileges, and no user interaction, making it straightforward to exploit once an attacker has code execution on the device (Apple iOS/iPadOS Advisory, Apple macOS Tahoe Advisory, Apple macOS Sequoia Advisory).
Successful exploitation allows a malicious application to gain root (superuser) privileges on the affected device, resulting in high confidentiality, integrity, and availability impact. An attacker with root access can read all user data, modify system files, install persistent malware, disable security controls, and potentially pivot to other connected systems or services. All affected platforms — iPhone, iPad, Mac, and Apple Vision Pro — are at risk of full device compromise if a malicious app is installed (Apple iOS/iPadOS Advisory, Apple visionOS Advisory).
/System, /usr/bin, /Library/LaunchDaemons) created by non-system processes; unexpected launch daemon or agent plist files added.kernel subsystem) indicating unusual privilege escalation events.Apple has released patches addressing CVE-2026-20626 in the following updates: iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Tahoe 26.3, and visionOS 26.3, all released on February 11, 2026. Users and administrators should update all affected Apple devices to these versions or later immediately via System Settings > Software Update (macOS) or Settings > General > Software Update (iOS/iPadOS/visionOS). No configuration-based workaround is available; patching is the only remediation. Organizations should prioritize patching devices with access to sensitive data or corporate networks (Apple iOS/iPadOS Advisory, Apple macOS Sequoia Advisory, Apple macOS Tahoe Advisory, Apple visionOS Advisory).
The February 2026 Apple security update batch, which includes CVE-2026-20626, received coverage from security news outlets and community forums. The jailbreak community on Reddit specifically discussed this CVE, with users reviewing it before updating their devices, suggesting interest in its potential for privilege escalation research. Security aggregators such as BeyondMachines and CyberInsider covered Apple's February 2026 patch cycle broadly, noting the volume of vulnerabilities addressed. No specific high-profile researcher commentary focused solely on CVE-2026-20626 has been identified (Reddit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."