
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20687 is a use-after-free (UAF) vulnerability in the Apple kernel affecting multiple Apple operating systems. The flaw resides in the Kernel component and allows a malicious app to cause unexpected system termination or write to kernel memory. It was disclosed by Apple on March 24, 2026, and affects iOS and iPadOS prior to 18.7.7 and 26.4, macOS Sequoia prior to 15.7.5, macOS Tahoe prior to 26.4, tvOS prior to 26.4, and watchOS prior to 26.4. The vulnerability was discovered by Johnny Franks (@zeroxjf) and carries a CVSS v3.1 base score of 7.1 (High) (Apple iOS 26.4 Advisory, Apple iOS 18.7.7 Advisory, Apple macOS Tahoe Advisory).
The vulnerability is classified as CWE-416 (Use After Free) and stems from improper memory management in the Apple kernel. A publicly available proof-of-concept (PoC) on GitHub demonstrates exploitation via a race condition in the AppleSEPKeyStore driver, using multi-threaded IOConnectCallMethod/IOServiceClose calls to trigger the UAF condition, reliably causing kernel panics on vulnerable devices. Exploitation requires local access and user interaction (e.g., running a malicious app), with no privileges required. A second PoC targeting the AppleJPEGDriver was also published later (PoC GitHub - SEPKeyStore, PoC GitHub - JPEGDriver).
Successful exploitation can result in unexpected system termination (kernel panic/device crash) or unauthorized writes to kernel memory, impacting both availability and integrity of the affected device. Because the vulnerability allows writing to kernel memory, it could theoretically be chained with other vulnerabilities to achieve privilege escalation or persistent kernel-level compromise, though the current public PoC only demonstrates denial-of-service via kernel panic. Confidentiality is not directly impacted by this vulnerability alone (Apple iOS 18.7.7 Advisory, Apple macOS Sequoia Advisory).
IOConnectCallMethod and IOServiceClose calls to create a race condition.IOConnectCallMethod and IOServiceClose on the vulnerable driver, causing a use-after-free condition in kernel memory.panic.ips or panic-full.ips) referencing AppleSEPKeyStore or AppleJPEGDriver in the panic backtrace; system crash reports generated shortly after running an unknown or untrusted app.AppleSEPKeyStore or AppleJPEGDriver.IOConnectCallMethod and IOServiceClose calls to kernel drivers; processes spawning many threads targeting IOKit user clients.Apple has released patches addressing CVE-2026-20687 through improved memory management. Users should update to the following versions or later: iOS 18.7.7, iPadOS 18.7.7, iOS 26.4, iPadOS 26.4, macOS Sequoia 15.7.5, macOS Tahoe 26.4, tvOS 26.4, and watchOS 26.4. As a precautionary measure, avoid installing apps from untrusted sources until devices are patched. No configuration-based workaround is available; updating to a patched OS version is the only effective remediation (Apple iOS 18.7.7 Advisory, Apple macOS Sequoia Advisory, Apple macOS Tahoe Advisory).
Media coverage highlighted the iOS 18.7.7 update in the context of the broader "DarkSword" exploit campaign, with outlets such as Forbes, GBHackers, CyberSecurityNews, and CyberPress reporting on Apple's expanded rollout of the update to additional devices. The CIS issued an advisory noting multiple vulnerabilities in Apple products that could allow privilege escalation. Security community discussion focused on the availability of the public PoC and the kernel-write primitive, though no weaponized exploit has been reported (Forbes, CIS Advisory, GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."