
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20633 is a symlink handling vulnerability in Apple macOS affecting the Archive Utility (macOS Sonoma, macOS Tahoe) and DesktopServices (macOS Sequoia) components. The flaw allows a malicious app to access user-sensitive data by exploiting improper symlink resolution before file access (CWE-59). It affects macOS Sonoma versions before 14.8.5, macOS Sequoia versions before 15.7.5, and macOS Tahoe versions before 26.4. Apple disclosed and patched the vulnerability on March 24, 2026. It carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Sonoma Advisory, Apple Sequoia Advisory, Apple Tahoe Advisory).
The vulnerability is classified as CWE-59 (Improper Link Resolution Before File Access — 'Link Following'), commonly known as a symlink attack. The affected components — Archive Utility and DesktopServices — fail to properly validate symbolic links during file operations, allowing a malicious application to craft symlinks that redirect file access to sensitive user data outside the intended scope. Exploitation requires local access and user interaction (e.g., a user running a malicious app), with no privileges required. Apple addressed the issue with improved handling of symlinks in the patched releases. The vulnerability was discovered and reported by Mickey Jin (@patch1t) (Apple Sonoma Advisory, Apple Sequoia Advisory, Apple Tahoe Advisory).
Successful exploitation allows a malicious app to access user-sensitive data that it would not normally be permitted to read, resulting in a high confidentiality impact. There is no integrity or availability impact associated with this vulnerability. The attack is locally scoped and does not directly enable lateral movement or remote code execution, but unauthorized access to sensitive files could expose credentials, personal data, or other protected information that could facilitate further attacks (Apple Sonoma Advisory, Apple Sequoia Advisory).
Apple has released patches addressing CVE-2026-20633 in the following macOS updates released March 24, 2026: macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, and macOS Tahoe 26.4. Users should update their macOS systems to these versions or later via System Settings > Software Update. No configuration-based workarounds have been published; upgrading to a patched version is the only recommended remediation (Apple Sonoma Advisory, Apple Sequoia Advisory, Apple Tahoe Advisory).
The vulnerability was part of a broader Apple security update in March 2026 that addressed over 140 vulnerabilities across macOS, iOS, iPadOS, and tvOS. Security community coverage noted the scale of the patch release, though CVE-2026-20633 itself did not attract significant individual attention given its medium severity and local-only attack vector. The SANS Internet Storm Center and CIS Security both published advisories covering the broader Apple March 2026 update batch (SANS ISC Diary, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."