CVE-2026-20628
macOS vulnerability analysis and mitigation

Overview

CVE-2026-20628 is a sandbox escape vulnerability in Apple's Sandbox component affecting iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. The flaw stems from a permissions issue that was addressed with additional restrictions, allowing a malicious app to break out of its sandbox environment. It was disclosed and patched on February 11, 2026, and was discovered by Noah Gregory (wts.dev). Affected versions include iOS and iPadOS before 18.7.5 and before 26.3, macOS Sonoma before 14.8.4, macOS Sequoia before 15.7.4, macOS Tahoe before 26.3, tvOS before 26.3, visionOS before 26.3, and watchOS before 26.3. The vulnerability carries a CVSS v3.1 base score of 7.1 (High) (Apple Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control) and resides in the Sandbox component across Apple's operating system family. The root cause is a permissions issue — insufficient restrictions that allow an app to exceed its sandboxed execution context and interact with resources or processes outside its permitted scope. Exploitation requires local access and user interaction (e.g., a user running a malicious app), with no privileges required, making it accessible to any installed application. No public technical write-up or proof-of-concept code has been identified at this time (Apple Advisory iOS 26.3, Apple Advisory macOS Sequoia).

Impact

Successful exploitation allows a malicious app to escape its sandbox, potentially gaining access to data, files, or system resources belonging to other apps or the operating system itself. The primary impacts are high confidentiality loss (access to sensitive user data outside the app's permitted scope) and high integrity impact (ability to modify data or interact with protected system areas), with no direct availability impact per the CVSS assessment. This could facilitate further privilege escalation or lateral movement within the device if chained with other vulnerabilities (Apple Advisory iOS 18.7.5, Apple Advisory watchOS 26.3).

Mitigation and workarounds

Apple has released patches addressing CVE-2026-20628 across all affected platforms. Users should update to the following versions or later: iOS 18.7.5, iPadOS 18.7.5, iOS 26.3, iPadOS 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, and watchOS 26.3. Updates can be applied via Settings > General > Software Update on iOS/iPadOS/watchOS, or System Settings > General > Software Update on macOS. No configuration-based workarounds have been published; upgrading to a patched version is the only recommended remediation (Apple Advisory iOS 18.7.5, Apple Advisory macOS Sequoia, Apple Advisory iOS 26.3).

Community reactions

The vulnerability was part of a broader February 2026 Apple security update that addressed over 90 vulnerabilities across Apple's product ecosystem, which received coverage from technology media outlets. Security community coverage noted the breadth of the update, with some outlets highlighting the simultaneous patching of an actively exploited zero-day (CVE-2026-20700 in dyld) in the same release cycle. No specific researcher commentary or notable social media discussion focused exclusively on CVE-2026-20628 has been identified (Cyber Insider, Beyond Machines).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management