
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20677 is a race condition vulnerability in Apple's symbolic link handling within the Messages component that allows a shortcut to bypass sandbox restrictions. Discovered and reported by Ron Masas of BreakPoint.SH, it was disclosed and patched on February 11, 2026. Affected platforms include iOS (before 18.7.5 and 26.0–26.3), iPadOS (before 18.7.5 and 26.0–26.3), macOS Sonoma (before 14.8.4), macOS Tahoe (26.0–26.3), and visionOS (before 26.3). The vulnerability carries a CVSS v3.1 base score of 9.0 (Critical) (Apple iOS 26.3 Advisory, Apple iOS 18.7.5 Advisory, Apple macOS Tahoe Advisory).
The vulnerability is classified under CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization) and CWE-367 (Time-of-Check Time-of-Use / TOCTOU Race Condition). The flaw exists in the Messages component's handling of symbolic links, where a race condition between the time a symlink is checked and the time it is used allows a malicious shortcut to redirect file operations outside its sandboxed environment. An attacker can exploit this TOCTOU window to substitute a symlink target between the security check and the actual file operation, effectively bypassing Apple's sandbox restrictions without requiring user interaction or elevated privileges. Apple addressed the issue with improved handling of symbolic links (Apple iOS 26.3 Advisory, Apple macOS Sonoma Advisory).
Successful exploitation allows a malicious shortcut to escape its sandbox and access resources or capabilities normally restricted by Apple's security boundaries, with high impact to confidentiality, integrity, and availability. An attacker could leverage this to read sensitive user data, modify protected files, or disrupt system availability across iOS, iPadOS, macOS, and visionOS devices. The changed scope in the CVSS vector indicates the impact extends beyond the vulnerable component itself, potentially enabling access to other system resources or user data outside the shortcut's permitted scope (Apple iOS 18.7.5 Advisory, Apple visionOS Advisory).
/var/mobile/Library/, user data folders) from within shortcut or Messages sandbox directories.Messages or shortcuts process to paths outside their designated sandbox containers; abnormal shortcut execution activity correlated with file system changes in protected directories.Apple has released patches addressing this vulnerability across all affected platforms. Users should update to: iOS 18.7.5 or iOS 26.3 (and later), iPadOS 18.7.5 or iPadOS 26.3 (and later), macOS Sonoma 14.8.4 (and later), macOS Tahoe 26.3 (and later), and visionOS 26.3 (and later). No configuration-based workarounds are available; applying the vendor-supplied updates is the only effective remediation. Organizations with sensitive data environments should prioritize patching and consider restricting untrusted shortcut execution until systems are fully updated (Apple iOS 26.3 Advisory, Apple macOS Sonoma Advisory, Apple visionOS Advisory).
The vulnerability was credited to Ron Masas of BreakPoint.SH across all Apple security advisories, indicating responsible disclosure. Coverage appeared on security-focused outlets and aggregators shortly after Apple's February 11, 2026 disclosure, including ISC SANS and The Hacker Wire (ISC SANS). Social media discussion was noted on Bluesky via The Hacker Wire's account. General community reaction focused on the broader February 2026 Apple security update batch, which addressed over 90 vulnerabilities across Apple platforms (BeyondMachines).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."