
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20667 is a sandbox escape vulnerability in Apple's libxpc component affecting iOS, iPadOS, macOS, and watchOS. A logic issue in sandbox validation allows a locally installed app to break out of its sandbox environment without user interaction. The vulnerability was disclosed and patched on February 11, 2026, and was reported by an anonymous researcher. It carries a CVSS v3.1 base score of 8.8 (High) (Apple iOS/iPadOS Advisory, Apple macOS Tahoe Advisory, Feedly).
The vulnerability is rooted in a logic flaw within the libxpc inter-process communication library (CWE-693: Protection Mechanism Failure), which Apple addressed with improved validation checks. The attack vector is local, requiring only low privileges, and no user interaction is needed; the changed scope indicates the vulnerability allows an app to affect resources outside its sandbox boundary. Specifically, a malicious app can exploit the flawed sandbox enforcement logic in libxpc to escape its restricted execution environment and interact with system resources it should not be able to access. No public proof-of-concept or detailed technical write-up has been published as of the time of this report (Apple iOS/iPadOS Advisory, Apple macOS Sequoia Advisory, Feedly).
Successful exploitation allows a malicious app to escape its sandbox and gain unauthorized access to sensitive system resources, potentially executing arbitrary code outside sandbox restrictions with high impact to confidentiality, integrity, and availability. The changed scope means the impact extends beyond the sandboxed app itself to the broader operating system environment. This is particularly dangerous in scenarios where a malicious app is already installed on a device, as no user interaction is required to trigger the escape (Feedly, Apple iOS/iPadOS Advisory).
Apple has released patches addressing this vulnerability across all affected platforms. Users should update to the following versions: iOS 26.3, iPadOS 26.3, watchOS 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, or macOS Tahoe 26.3. As a supplementary measure, organizations should implement application allowlisting policies to restrict installation of untrusted apps and monitor for suspicious app behavior indicative of sandbox escape attempts (Apple iOS/iPadOS Advisory, Apple macOS Sonoma Advisory, Apple watchOS Advisory).
The vulnerability was covered by security news outlets including Cyber Insider and BeyondMachines in the context of Apple's broader February 2026 security update, which addressed over 90 vulnerabilities across iOS, macOS, and iPadOS. Social media discussion was noted on Mastodon and Bluesky via The Hacker Wire. The SANS Internet Storm Center also published a diary entry covering the February 2026 Apple security releases (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."