CVE-2026-20699
macOS vulnerability analysis and mitigation

Overview

CVE-2026-20699 is a downgrade vulnerability affecting Intel-based Mac computers, specifically within the Spotlight and AppleMobileFileIntegrity components of macOS. Insufficient code-signing restrictions allow a local application to bypass security controls and access user-sensitive data. The vulnerability was first addressed in macOS Tahoe 26.3 (released February 11, 2026) and subsequently patched in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4 (all released March 24, 2026). It carries a CVSS v3.1 base score of 6.2 (Medium), classified under CWE-347 (Improper Verification of Cryptographic Signature) (Apple Advisory 126348, Apple Advisory 126795, Apple Advisory 126796).

Technical details

The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature), where macOS failed to enforce adequate code-signing restrictions on Intel-based hardware, enabling a downgrade attack. An attacker-controlled application could exploit this weakness to circumvent macOS security controls — specifically within the Spotlight and AppleMobileFileIntegrity subsystems — and gain unauthorized access to user-sensitive data. The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), making it exploitable by any unprivileged local application on affected Intel-based Macs. The fix involved adding additional code-signing restrictions to prevent the downgrade condition. The vulnerability was discovered and reported by Mickey Jin (@patch1t) (Apple Advisory 126348, Apple Advisory 126794).

Impact

Successful exploitation allows a malicious application running locally on an Intel-based Mac to access user-sensitive data without requiring elevated privileges or user interaction. The primary impact is a confidentiality breach (high confidentiality impact per CVSS), as the vulnerability enables unauthorized data access through bypassed code-signing enforcement. There is no integrity or availability impact reported, and the scope is unchanged, limiting the blast radius to the affected system rather than enabling lateral movement (Apple Advisory 126795, Apple Advisory 126796).

Mitigation and workarounds

Apple has released patches addressing CVE-2026-20699 across all supported macOS versions. Users should update to one of the following patched releases: macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, macOS Tahoe 26.3, or macOS Tahoe 26.4. No configuration-based workarounds have been published; upgrading to a patched version is the only recommended remediation. Note that this vulnerability is specific to Intel-based Mac computers and does not affect Apple Silicon Macs (Apple Advisory 126794, Apple Advisory 126795, Apple Advisory 126796).

Community reactions

The vulnerability was included in Apple's March 2026 security update batch, which addressed over 140 vulnerabilities across macOS, iOS, iPadOS, and tvOS. Security aggregators such as BeyondMachines and the SANS Internet Storm Center noted the breadth of the March 2026 Apple security releases. The CIS (Center for Internet Security) issued an advisory covering multiple vulnerabilities in Apple products from this update cycle, categorizing the overall risk as potentially allowing privilege escalation (SANS ISC, CIS Advisory).

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64783NONEN/A
  • Apple Safari logoApple Safari
  • WebKit
NoYesJul 27, 2026
CVE-2026-64776NONEN/A
  • macOS logomacOS
  • Disk Images
NoYesJul 27, 2026
CVE-2026-64775NONEN/A
  • macOS logomacOS
  • Kernel
NoYesJul 27, 2026
CVE-2026-64774NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026
CVE-2026-64772NONEN/A
  • macOS logomacOS
  • Model I/O
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management