
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20658 is a package validation vulnerability in Apple macOS Tahoe that allows a local app to gain root privileges. The root cause is a package validation issue in the Security framework component, which Apple addressed by blocking the vulnerable package. It affects macOS Tahoe versions from 26.0 up to (but not including) 26.3, and was disclosed and patched on February 11, 2026, with an additional security update released on April 29, 2026. The vulnerability carries a CVSS v3.1 base score of 7.8 (High), and was discovered by the researcher known as "Pwn2car" (Apple Advisory).
The vulnerability is classified as a package validation issue (CWE-20, Improper Input Validation) within the Security framework component of macOS Tahoe. An attacker with low-privileged local access can exploit this flaw — without any user interaction — by leveraging a malicious or crafted package that bypasses validation checks, ultimately allowing privilege escalation to root. Apple's remediation was to block the vulnerable package entirely rather than patching the validation logic itself, suggesting the flaw was tied to a specific package or package type that could be abused for privilege escalation (Apple Advisory).
Successful exploitation allows a local application to escalate privileges to root on affected macOS Tahoe systems, resulting in high confidentiality, integrity, and availability impact. An attacker achieving root access could read or exfiltrate sensitive user and system data, modify or destroy system files, install persistent malware, and potentially pivot to other systems or services accessible from the compromised host. The scope is limited to the local system, but root-level compromise represents a complete loss of system control (Apple Advisory).
Apple patched CVE-2026-20658 in macOS Tahoe 26.3, released February 11, 2026, by blocking the vulnerable package. Users and administrators should update all affected macOS Tahoe systems (versions 26.0 through 26.2) to macOS Tahoe 26.3 or later immediately. No configuration-based workaround has been published; upgrading to the patched release is the only recommended remediation (Apple Advisory).
The vulnerability was reported by the researcher "Pwn2car" and disclosed as part of Apple's February 2026 security update batch, which addressed over 90 vulnerabilities across macOS, iOS, and iPadOS. Coverage appeared on security news aggregators and threat intelligence platforms shortly after disclosure, with BeyondMachines noting the breadth of Apple's February 2026 patch cycle. No significant independent researcher commentary or social media discussion specific to CVE-2026-20658 has been identified beyond standard vulnerability tracking (Apple Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."