
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20694 is a symlink following vulnerability in Apple's MigrationKit component that allows a local app to access user-sensitive data. It affects iOS and iPadOS (before 26.3), macOS Sonoma (before 14.8.4 and 14.8.5), macOS Sequoia (before 15.7.4 and 15.7.5), and macOS Tahoe (before 26.3 and 26.4). The vulnerability was discovered by Rodolphe Brunetti (@eisw0lf) of Lupus Nova and publicly disclosed on March 24, 2026, when Apple released the corresponding security advisories. It carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory iOS 26.3, Apple Advisory macOS Tahoe 26.3, Apple Advisory macOS Sequoia 15.7.4, Apple Advisory macOS Sonoma 14.8.4).
The vulnerability is classified under CWE-59 (Improper Link Resolution Before File Access / 'Link Following') and CWE-61 (UNIX Symbolic Link Following), residing in Apple's MigrationKit component. An attacker-controlled app can craft or manipulate symbolic links that MigrationKit follows without adequate validation during file access operations, enabling the app to read files outside its intended scope. Exploitation requires local access with low privileges and no user interaction, making it straightforward for a malicious app already installed on the device to leverage. No public proof-of-concept code has been identified (Apple Advisory iOS 26.3, Apple Advisory macOS Tahoe 26.3).
Successful exploitation allows a low-privileged local app to read user-sensitive data that it would not normally be permitted to access, resulting in a high confidentiality impact with no effect on integrity or availability. The affected asset scope is limited to the local device, but the data exposed could include personal files, credentials, or other sensitive information processed or staged by MigrationKit. There is no evidence of lateral movement capability directly from this vulnerability, though exfiltrated data could facilitate further attacks (Apple Advisory macOS Sequoia 15.7.4, Apple Advisory macOS Sonoma 14.8.4).
/Users/<username>/, ~/Library/, or other protected paths.unified system log via log show) showing MigrationKit accessing files in unexpected locations or outside its normal operational scope.Apple has released patches addressing this vulnerability across all affected platforms. Users should update to the following versions or later: iOS 26.3, iPadOS 26.3, macOS Sonoma 14.8.4 (or 14.8.5), macOS Sequoia 15.7.4 (or 15.7.5), and macOS Tahoe 26.3 (or 26.4). No configuration-based workarounds have been published; upgrading to a patched OS version is the only recommended remediation. Given the low attack complexity and high confidentiality impact, patching should be prioritized (Apple Advisory iOS 26.3, Apple Advisory macOS Tahoe 26.3, Apple Advisory macOS Sequoia 15.7.4, Apple Advisory macOS Sonoma 14.8.4, Apple Advisory macOS Tahoe 26.4).
The vulnerability was part of a broader set of over 140 security fixes released by Apple in its February–March 2026 security update cycle, which received general coverage from security news outlets and aggregators. The CIS Advisory noted multiple vulnerabilities in Apple products patched in this release cycle. No specific notable researcher commentary or significant social media discussion focused exclusively on CVE-2026-20694 has been identified beyond the discoverer credit to Rodolphe Brunetti (@eisw0lf) of Lupus Nova (Apple Advisory iOS 26.3).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."