
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20657 is a buffer overflow vulnerability in Apple's Vision framework component affecting multiple Apple operating systems. The flaw was disclosed on March 24, 2026, as part of Apple's March 2026 security update batch. Affected versions include iOS and iPadOS prior to 18.7.7, macOS Sonoma prior to 14.8.5, macOS Sequoia prior to 15.7.5, as well as macOS Tahoe 26.4, iOS/iPadOS 26.4, and visionOS 26.4. The vulnerability was discovered by Andrew Becker and carries a CVSS v3.1 base score of 6.5 (Medium) (Apple iOS Advisory, Apple macOS Sequoia Advisory, Apple macOS Sonoma Advisory).
The vulnerability is rooted in improper memory handling within Apple's Vision framework when parsing files, classified under CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer), with related weaknesses CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write). An attacker can exploit this by crafting a malicious file that, when parsed by the Vision component, triggers a buffer overflow condition. Exploitation requires user interaction — specifically, a user must open or process the maliciously crafted file — and no authentication or special privileges are required from the attacker. No public proof-of-concept code or detailed technical write-ups have been identified at this time (Apple macOS Sequoia Advisory, Feedly).
Successful exploitation results in an unexpected application termination (crash), constituting a denial-of-service condition for the affected application. There is no evidence of confidentiality or integrity impact — the CVSS score reflects a high availability impact only, with no confidentiality or integrity loss. The scope is limited to the affected application process and does not appear to enable code execution or lateral movement based on currently available information (Apple iOS Advisory, Apple macOS Sonoma Advisory).
/Library/Logs/DiagnosticReports/ on macOS or via the iOS crash reporter) referencing the Vision framework or file parsing routines.Apple has released patches addressing CVE-2026-20657 in the following versions: iOS 18.7.7 and iPadOS 18.7.7, macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, macOS Tahoe 26.4, iOS 26.4 and iPadOS 26.4, and visionOS 26.4. Users should update their devices to these versions or later as soon as possible. As a precautionary workaround prior to patching, users should avoid opening files from untrusted or unknown sources (Apple iOS Advisory, Apple macOS Sequoia Advisory, Apple macOS Sonoma Advisory).
The vulnerability was covered as part of broader reporting on Apple's March 2026 security update, which addressed over 140 vulnerabilities across Apple platforms. Security news outlets such as iClarified noted the significance of the iOS 18.7.7 and iPadOS 18.7.7 releases. The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in Apple products from this update cycle. No notable individual researcher commentary specific to CVE-2026-20657 has been identified (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."