CVE-2026-20694
macOS vulnerability analysis and mitigation

Overview

CVE-2026-20694 is a symlink following vulnerability in Apple's MigrationKit component that allows a local app to access user-sensitive data. It affects iOS and iPadOS (before 26.3), macOS Sonoma (before 14.8.4 and 14.8.5), macOS Sequoia (before 15.7.4 and 15.7.5), and macOS Tahoe (before 26.3 and 26.4). The vulnerability was discovered by Rodolphe Brunetti (@eisw0lf) of Lupus Nova and publicly disclosed on March 24, 2026, when Apple released the corresponding security advisories. It carries a CVSS v3.1 base score of 5.5 (Medium) (Apple Advisory iOS 26.3, Apple Advisory macOS Tahoe 26.3, Apple Advisory macOS Sequoia 15.7.4, Apple Advisory macOS Sonoma 14.8.4).

Technical details

The vulnerability is classified under CWE-59 (Improper Link Resolution Before File Access / 'Link Following') and CWE-61 (UNIX Symbolic Link Following), residing in Apple's MigrationKit component. An attacker-controlled app can craft or manipulate symbolic links that MigrationKit follows without adequate validation during file access operations, enabling the app to read files outside its intended scope. Exploitation requires local access with low privileges and no user interaction, making it straightforward for a malicious app already installed on the device to leverage. No public proof-of-concept code has been identified (Apple Advisory iOS 26.3, Apple Advisory macOS Tahoe 26.3).

Impact

Successful exploitation allows a low-privileged local app to read user-sensitive data that it would not normally be permitted to access, resulting in a high confidentiality impact with no effect on integrity or availability. The affected asset scope is limited to the local device, but the data exposed could include personal files, credentials, or other sensitive information processed or staged by MigrationKit. There is no evidence of lateral movement capability directly from this vulnerability, though exfiltrated data could facilitate further attacks (Apple Advisory macOS Sequoia 15.7.4, Apple Advisory macOS Sonoma 14.8.4).

Exploitation steps

  1. Install a malicious app: The attacker distributes or side-loads a malicious app onto the target Apple device running a vulnerable version of iOS, iPadOS, or macOS.
  2. Identify MigrationKit activity: The malicious app monitors or triggers conditions under which MigrationKit processes files, such as during a device migration or data transfer operation.
  3. Plant a crafted symlink: The app creates a symbolic link in a location accessible to MigrationKit, pointing to a sensitive file or directory (e.g., user documents, keychain-adjacent files, or application data) that the app would not normally be permitted to read.
  4. Trigger symlink traversal: The app initiates or waits for MigrationKit to process the directory containing the crafted symlink, causing MigrationKit to follow the symlink without proper validation.
  5. Access sensitive data: MigrationKit reads the target of the symlink, and the malicious app retrieves the sensitive user data from the resolved path, bypassing normal access controls (Apple Advisory iOS 26.3, Apple Advisory macOS Tahoe 26.3).

Indicators of compromise

  • File System: Unexpected symbolic links created in directories accessible to MigrationKit, particularly pointing to sensitive user data locations outside the app's sandbox.
  • File System: Unusual file access patterns in MigrationKit's working directories, such as newly created symlinks referencing /Users/<username>/, ~/Library/, or other protected paths.
  • Logs: System logs (e.g., unified system log via log show) showing MigrationKit accessing files in unexpected locations or outside its normal operational scope.
  • Process: MigrationKit process activity initiated outside of expected migration workflows (e.g., triggered by a third-party app rather than a user-initiated migration).

Mitigation and workarounds

Apple has released patches addressing this vulnerability across all affected platforms. Users should update to the following versions or later: iOS 26.3, iPadOS 26.3, macOS Sonoma 14.8.4 (or 14.8.5), macOS Sequoia 15.7.4 (or 15.7.5), and macOS Tahoe 26.3 (or 26.4). No configuration-based workarounds have been published; upgrading to a patched OS version is the only recommended remediation. Given the low attack complexity and high confidentiality impact, patching should be prioritized (Apple Advisory iOS 26.3, Apple Advisory macOS Tahoe 26.3, Apple Advisory macOS Sequoia 15.7.4, Apple Advisory macOS Sonoma 14.8.4, Apple Advisory macOS Tahoe 26.4).

Community reactions

The vulnerability was part of a broader set of over 140 security fixes released by Apple in its February–March 2026 security update cycle, which received general coverage from security news outlets and aggregators. The CIS Advisory noted multiple vulnerabilities in Apple products patched in this release cycle. No specific notable researcher commentary or significant social media discussion focused exclusively on CVE-2026-20694 has been identified beyond the discoverer credit to Rodolphe Brunetti (@eisw0lf) of Lupus Nova (Apple Advisory iOS 26.3).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management