
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20698 is a kernel memory corruption vulnerability in Apple operating systems caused by improper memory handling, allowing a local app to cause unexpected system termination or corrupt kernel memory. It was discovered by DARKNAVY (@DarkNavyOrg) and disclosed on March 24, 2026, as part of Apple's security update release. Affected platforms include iOS and iPadOS (before 26.4), macOS Tahoe (before 26.4), tvOS (before 26.4), visionOS (before 26.4), and watchOS (before 26.4) (Apple iOS/iPadOS Advisory, Apple macOS Advisory). The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Feedly).
The root cause is classified as CWE-787 (Out-of-bounds Write) and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) in the Apple kernel component. The vulnerability is exploitable locally by a low-privileged app without requiring user interaction, targeting the PF_ROUTE socket handling subsystem — specifically a heap overflow condition that can be triggered via crafted routing socket operations. A public PoC repository (CVE-2026-20698-PF_ROUTE-Heap-Overflow) includes multiple C programs such as pf_route_crash.c and variant_probe.c that demonstrate triggering a kernel panic or heap overflow on vulnerable iOS/macOS systems, with a confirmed kernel panic log from an iPhone 17 Pro Max on iOS 26.3.1 (GitHub PoC, Apple iOS/iPadOS Advisory).
Successful exploitation allows a low-privileged local application to corrupt kernel memory or cause unexpected system termination (kernel panic), resulting in high impacts to confidentiality, integrity, and availability. Kernel memory corruption can potentially be leveraged for privilege escalation, enabling an attacker to break out of the app sandbox and gain elevated control over the affected device. All major Apple platforms are affected, including iPhones, iPads, Macs, Apple TVs, Apple Watches, and Apple Vision Pro devices running versions prior to the 26.4 release (Apple iOS/iPadOS Advisory, Apple macOS Advisory, Apple tvOS Advisory).
pf_route_crash.c from the public PoC) to write out-of-bounds data into kernel heap memory via the PF_ROUTE socket interface..ips files) in /Library/Logs/DiagnosticReports/ or accessible via Settings > Privacy & Security > Analytics & Improvements, particularly those referencing routing socket or network subsystem panics.pf_route_crash, variant_probe) in app containers or temporary directories on macOS.PF_ROUTE) or perform abnormal socket operations without a clear network management purpose.route socket activity observable via system monitoring tools such as netstat or fs_usage on macOS.Apple has released patches for all affected platforms: iOS 26.4, iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, and watchOS 26.4, all released on March 24, 2026 (Apple iOS/iPadOS Advisory, Apple macOS Advisory). Users should immediately apply available system updates on all affected Apple devices via Settings > General > Software Update (iOS/iPadOS/watchOS/tvOS/visionOS) or System Settings > General > Software Update (macOS). No vendor-provided workarounds are available; updating to the patched version is the only recommended remediation. Organizations should prioritize devices actively used or exposed to untrusted third-party applications.
The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Apple products patched in this release could allow for privilege escalation, recommending prompt updates (CIS Advisory). Forbes issued a warning to all iPhone users to update to iOS 26.4 promptly following the release (Forbes). DARKNAVY (@DarkNavyOrg), the discovering research team, was credited by Apple across multiple platform advisories and also acknowledged for additional kernel-related findings in the same update cycle, indicating active research focus on Apple kernel security.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."