CVE-2026-20651
macOS vulnerability analysis and mitigation

Overview

CVE-2026-20651 is a privacy vulnerability in the Messages component of Apple macOS caused by insecure handling of temporary files (CWE-377). It allows a local app to access sensitive user data without authorization. The vulnerability affects macOS Sonoma (14.0–14.8.4), macOS Sequoia (15.0–15.7.5), and macOS Tahoe (26.0–26.3). It was disclosed by Apple on March 24, 2026, and credited to Chunyu Song of NorthSea. It carries a CVSS v3.1 base score of 6.2 (Medium) (Apple Advisory 126795, Apple Advisory 126350, Apple Advisory 126348).

Technical details

The root cause is classified as CWE-377 (Insecure Temporary File), where the Messages component creates or uses temporary files with insufficient access controls, allowing other apps to read their contents. The attack vector is local (AV:L), requires no privileges (PR:N) and no user interaction (UI:N), and has low attack complexity (AC:L). An attacker-controlled app running on the same system could monitor or read improperly secured temporary files created by Messages, potentially exposing sensitive user data such as message content or attachments. No public proof-of-concept or technical write-up detailing the specific exploitation mechanism has been published (Apple Advisory 126795, Apple Advisory 126350).

Impact

Successful exploitation results in a high confidentiality impact — a local app can read sensitive user data handled by the Messages application, such as message content or associated files, without user knowledge or consent. There is no integrity or availability impact. The scope is limited to the local system, but the exposed data could include private communications, potentially enabling further social engineering or targeted attacks (Apple Advisory 126795, Apple Advisory 126348).

Mitigation and workarounds

Apple has released patches addressing this vulnerability across all affected macOS branches. Users should update to macOS Sonoma 14.8.5 or later, macOS Sequoia 15.7.5 or later, or macOS Tahoe 26.3 or later. No configuration-based workarounds have been published; upgrading to a patched release is the only recommended remediation (Apple Advisory 126795, Apple Advisory 126350, Apple Advisory 126348).

Community reactions

The vulnerability was noted in broader coverage of Apple's March 2026 security update cycle, which addressed over 140 vulnerabilities across macOS, iOS, iPadOS, and tvOS. CIS published an advisory noting multiple vulnerabilities in Apple products that could allow for privilege escalation. No significant individual researcher commentary or social media discussion specific to CVE-2026-20651 has been identified beyond standard patch reporting.

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management