
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20649 is a logging information disclosure vulnerability in Apple's Game Center component that allows a user to view sensitive user information. It affects macOS Tahoe, iOS, iPadOS, tvOS, and watchOS prior to version 26.3. The vulnerability was disclosed and patched on February 11, 2026, with Apple releasing fixes across all affected platforms simultaneously. It carries a CVSS v3.1 base score of 7.5 (High), reflecting a network-accessible, unauthenticated attack vector with high confidentiality impact (Apple iOS/iPadOS Advisory, Apple macOS Advisory, Feedly).
The root cause is a logging issue in the Game Center component where sensitive user information was not properly redacted from log output, classified under CWE-377 (Insecure Temporary File) per Feedly's analysis, though the Apple advisory describes it as a logging deficiency addressed with improved data redaction. The vulnerability does not require user interaction or special privileges to trigger based on the CVSS vector (AV:N/AC:L/PR:N/UI:N), suggesting that log data containing sensitive information could be accessible without authentication under certain conditions. Apple credited researcher Asaf Cohen with discovering the vulnerability (Apple iOS/iPadOS Advisory, Apple macOS Advisory, Apple tvOS Advisory, Apple watchOS Advisory).
Successful exploitation results in disclosure of sensitive user information logged by the Game Center component, impacting confidentiality with no effect on integrity or availability. The scope of exposed data is limited to what Game Center logs, which may include user account details or activity information. There is no evidence of lateral movement potential or broader system compromise associated with this vulnerability (Apple iOS/iPadOS Advisory, Apple macOS Advisory).
Apple has released patches addressing CVE-2026-20649 across all affected platforms: iOS 26.3 and iPadOS 26.3 (for iPhone 11 and later, and supported iPad models), macOS Tahoe 26.3, tvOS 26.3 (for Apple TV HD and Apple TV 4K), and watchOS 26.3 (for Apple Watch Series 6 and later). Users should update their devices to these versions or later via the standard software update mechanism. No configuration-based workarounds have been published by Apple (Apple iOS/iPadOS Advisory, Apple macOS Advisory, Apple tvOS Advisory, Apple watchOS Advisory).
The vulnerability received routine coverage as part of Apple's February 2026 security update cycle, with security news outlets and aggregators such as The Hacker Wire and Gigazine noting the iOS 26.3 release. No significant independent researcher commentary or notable community debate specific to CVE-2026-20649 has been identified beyond standard vulnerability database entries (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."