
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20669 is a path traversal vulnerability in the Admin Framework component of Apple macOS Tahoe, where a parsing issue in the handling of directory paths could allow a malicious app to access sensitive user data. The vulnerability was disclosed on February 11, 2026, as part of Apple's security update for macOS Tahoe 26.3. It affects macOS Tahoe versions prior to 26.3 and was credited to researcher Mickey Jin (@patch1t). The CVSS v3.1 base score is 5.5 (Medium) (Apple Advisory).
The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'), stemming from insufficient validation of directory path inputs within macOS's Admin Framework component. An attacker with a low-privileged local app can exploit the parsing flaw to traverse outside intended directory boundaries and read sensitive user data without requiring elevated privileges or user interaction. Apple addressed the issue with improved path validation logic in macOS Tahoe 26.3 (Apple Advisory).
Successful exploitation allows a locally installed, low-privileged application to access sensitive user data that it should not be permitted to read, resulting in a high confidentiality impact with no integrity or availability impact. The vulnerability is locally scoped and does not enable code execution or system-wide compromise on its own, but unauthorized data access could expose personal files, credentials, or other protected information stored on the affected macOS system (Apple Advisory).
Apple has patched this vulnerability in macOS Tahoe 26.3, released February 11, 2026. Users should update to macOS Tahoe 26.3 or later via System Settings > General > Software Update. No configuration-based workaround is available; upgrading to the patched release is the only recommended remediation (Apple Advisory).
The vulnerability was noted in standard security community aggregators and vulnerability tracking feeds shortly after Apple's disclosure, with no significant controversy or notable researcher commentary beyond the credit to Mickey Jin (@patch1t). Discussion on community forums such as TidBITS touched on the broader macOS Tahoe security update in the context of older OS security comparisons, but CVE-2026-20669 itself did not generate significant standalone attention (Apple Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."