CVE-2026-20641
macOS vulnerability analysis and mitigation

Overview

CVE-2026-20641 is a privacy vulnerability in Apple's StoreKit framework that allows a malicious app to identify what other apps a user has installed on their device. Discovered and reported by Gongyu Ma (@Mezone0), it was disclosed and patched on February 11, 2026. The vulnerability affects iOS and iPadOS (before 18.7.5 and before 26.3), macOS Sonoma (before 14.8.4), macOS Sequoia (before 15.7.4), macOS Tahoe (before 26.3), tvOS (before 26.3), visionOS (before 26.3), and watchOS (before 26.3). It carries a CVSS v3.1 base score of 7.1 (High), classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) (Apple iOS 18.7.5, Apple iOS 26.3, Apple macOS Sequoia).

Technical details

The vulnerability is rooted in insufficient input validation or access controls within the StoreKit framework (CWE-200), which is responsible for in-app purchases and app store interactions on Apple platforms. A locally installed malicious app can exploit this flaw to enumerate other applications installed on the user's device — information that should be inaccessible to third-party apps due to Apple's privacy sandbox model. The attack vector is local, requires user interaction (e.g., running the malicious app), and does not require elevated privileges. Apple addressed the issue with improved checks in the StoreKit component (Apple iOS 18.7.5, Apple watchOS 26.3, Apple visionOS 26.3).

Impact

Successful exploitation allows a sandboxed app to fingerprint a user's device by identifying which other apps are installed, which can reveal sensitive behavioral, financial, health, or religious preferences (e.g., presence of banking, dating, or religious apps). This information can be used for targeted social engineering, user profiling, or as reconnaissance for further attacks. The CVSS scoring reflects high confidentiality and integrity impact with no availability impact, scoped to the local device (Apple iOS 26.3, Apple macOS Sequoia).

Mitigation and workarounds

Apple has released patches across all affected platforms. Users should update to the following versions or later: iOS 18.7.5, iPadOS 18.7.5, iOS 26.3, iPadOS 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, and watchOS 26.3. No configuration-based workarounds have been published; updating to a patched OS version is the only recommended remediation. Users should apply updates promptly via Settings > General > Software Update on iOS/iPadOS or System Settings > General > Software Update on macOS (Apple iOS 18.7.5, Apple iOS 26.3, Apple macOS Sequoia).

Community reactions

The vulnerability was covered in security community aggregators and scanner platforms shortly after disclosure, including Tenable Nessus (plugin 298657) and Qualys (detection IDs 610759, 610760). Coverage appeared on ISC SANS and technology news outlets such as Gigazine. No notable independent researcher commentary or significant social media debate specific to this CVE has been identified beyond routine patch-cycle reporting.

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management