
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20636 is a memory handling vulnerability in Apple's WebKit browser engine that can cause an unexpected process crash when processing maliciously crafted web content. It was disclosed on February 11, 2026, as part of Apple's security updates for iOS 26.3, iPadOS 26.3, macOS Tahoe 26.3, Safari 26.3, and visionOS 26.3. All versions of the affected platforms prior to 26.3 are impacted. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), reflecting a network-based attack requiring user interaction with no privileges needed (Apple iOS/iPadOS Advisory, Apple Safari Advisory, Feedly).
The vulnerability is classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), indicating a memory buffer mismanagement issue within WebKit. Apple's advisory states the issue was addressed with improved memory handling, referencing WebKit Bugzilla entry 304657. An attacker can exploit this by crafting malicious web content that, when processed by the WebKit rendering engine, triggers an out-of-bounds or improper memory operation leading to a process crash. The vulnerability was discovered and reported by the researcher known as "EntryHi," who also reported the closely related CVE-2026-20635 (WebKit Bugzilla 304661) (Apple iOS/iPadOS Advisory, Apple Safari Advisory).
Successful exploitation results in an unexpected crash of the WebKit rendering process, causing a denial-of-service condition for the affected browser or web view. The CVSS scoring reflects a high availability impact with no confidentiality or integrity impact, meaning attackers cannot directly read or modify data through this vulnerability alone. Users visiting a malicious website or opening crafted web content on any unpatched Apple device — including iPhones, iPads, Macs, and Apple Vision Pro — would experience application or browser crashes (Apple iOS/iPadOS Advisory, Apple visionOS Advisory).
com.apple.WebKit.WebContent crash logs on macOS/iOS) correlated with visits to unknown or suspicious URLs.com.apple.WebKit.WebContent or Safari renderer processes, particularly when accessing external web content.Apple has released patches addressing CVE-2026-20636 in iOS 26.3, iPadOS 26.3, macOS Tahoe 26.3, Safari 26.3, and visionOS 26.3, all released on February 11, 2026. Users should update their Apple devices to these versions or later immediately via Settings > General > Software Update (iOS/iPadOS/visionOS) or System Settings > Software Update (macOS). No configuration-based workaround is available; upgrading to the patched release is the only remediation. Linux distributions shipping WebKit2GTK have also released corresponding patches (Debian DSA-6172-1, SUSE, Fedora, Ubuntu, Red Hat) (Apple iOS/iPadOS Advisory, Apple Safari Advisory, Apple macOS Advisory).
The February 2026 Apple security update batch received broad coverage from security media, with outlets such as CyberInsider noting Apple patched actively exploited zero-days in the same release cycle (referring to other CVEs in the batch, not CVE-2026-20636 specifically). The vulnerability was also tracked by downstream Linux ecosystem vendors including Red Hat, Debian, SUSE, Fedora, Ubuntu, and Amazon Linux, who issued their own WebKit2GTK advisories. No specific researcher commentary or social media discussion focused exclusively on CVE-2026-20636 has been identified beyond the discoverer credit to "EntryHi" in Apple's advisories (Apple iOS/iPadOS Advisory, Apple Safari Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."