CVE-2026-20687
macOS vulnerability analysis and mitigation

Overview

CVE-2026-20687 is a use-after-free (UAF) vulnerability in the Apple kernel affecting multiple Apple operating systems. The flaw resides in the Kernel component and allows a malicious app to cause unexpected system termination or write to kernel memory. It was disclosed by Apple on March 24, 2026, and affects iOS and iPadOS prior to 18.7.7 and 26.4, macOS Sequoia prior to 15.7.5, macOS Tahoe prior to 26.4, tvOS prior to 26.4, and watchOS prior to 26.4. The vulnerability was discovered by Johnny Franks (@zeroxjf) and carries a CVSS v3.1 base score of 7.1 (High) (Apple iOS 26.4 Advisory, Apple iOS 18.7.7 Advisory, Apple macOS Tahoe Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free) and stems from improper memory management in the Apple kernel. A publicly available proof-of-concept (PoC) on GitHub demonstrates exploitation via a race condition in the AppleSEPKeyStore driver, using multi-threaded IOConnectCallMethod/IOServiceClose calls to trigger the UAF condition, reliably causing kernel panics on vulnerable devices. Exploitation requires local access and user interaction (e.g., running a malicious app), with no privileges required. A second PoC targeting the AppleJPEGDriver was also published later (PoC GitHub - SEPKeyStore, PoC GitHub - JPEGDriver).

Impact

Successful exploitation can result in unexpected system termination (kernel panic/device crash) or unauthorized writes to kernel memory, impacting both availability and integrity of the affected device. Because the vulnerability allows writing to kernel memory, it could theoretically be chained with other vulnerabilities to achieve privilege escalation or persistent kernel-level compromise, though the current public PoC only demonstrates denial-of-service via kernel panic. Confidentiality is not directly impacted by this vulnerability alone (Apple iOS 18.7.7 Advisory, Apple macOS Sequoia Advisory).

Exploitation steps

  1. Obtain a vulnerable device: Identify an Apple device running iOS/iPadOS prior to 18.7.7 or 26.4, macOS Sequoia prior to 15.7.5, macOS Tahoe prior to 26.4, tvOS prior to 26.4, or watchOS prior to 26.4.
  2. Prepare malicious app: Develop or obtain an app embedding the UAF exploit code targeting the AppleSEPKeyStore or AppleJPEGDriver kernel extension, using multi-threaded IOConnectCallMethod and IOServiceClose calls to create a race condition.
  3. Deliver and execute the app: Convince the target user to install and run the malicious app (user interaction required). The app does not require elevated privileges to execute.
  4. Trigger the race condition: The app spawns multiple threads that simultaneously call IOConnectCallMethod and IOServiceClose on the vulnerable driver, causing a use-after-free condition in kernel memory.
  5. Achieve impact: The UAF condition results in a kernel panic (system crash/unexpected termination) or, with further exploitation, arbitrary writes to kernel memory that could be leveraged for privilege escalation (PoC GitHub - SEPKeyStore).

Indicators of compromise

  • Logs: Unexpected kernel panic logs (panic.ips or panic-full.ips) referencing AppleSEPKeyStore or AppleJPEGDriver in the panic backtrace; system crash reports generated shortly after running an unknown or untrusted app.
  • File System: Presence of unsigned or sideloaded apps with entitlements requesting IOKit service connections to AppleSEPKeyStore or AppleJPEGDriver.
  • Process: Unusual multi-threaded processes making rapid, repeated IOConnectCallMethod and IOServiceClose calls to kernel drivers; processes spawning many threads targeting IOKit user clients.
  • Network: No direct network indicators, as exploitation is local; however, post-exploitation activity may include outbound connections if the UAF is chained with a privilege escalation payload.

Mitigation and workarounds

Apple has released patches addressing CVE-2026-20687 through improved memory management. Users should update to the following versions or later: iOS 18.7.7, iPadOS 18.7.7, iOS 26.4, iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, and watchOS 26.4. As a precautionary measure, avoid installing apps from untrusted sources until devices are patched. No configuration-based workaround is available; updating to a patched OS version is the only effective remediation (Apple iOS 18.7.7 Advisory, Apple macOS Sequoia Advisory, Apple macOS Tahoe Advisory).

Community reactions

Media coverage highlighted the iOS 18.7.7 update in the context of the broader "DarkSword" exploit campaign, with outlets such as Forbes, GBHackers, CyberSecurityNews, and CyberPress reporting on Apple's expanded rollout of the update to additional devices. The CIS issued an advisory noting multiple vulnerabilities in Apple products that could allow privilege escalation. Security community discussion focused on the availability of the public PoC and the kernel-write primitive, though no weaponized exploit has been reported (Forbes, CIS Advisory, GBHackers).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management