
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20699 is a downgrade vulnerability affecting Intel-based Mac computers, specifically within the Spotlight and AppleMobileFileIntegrity components of macOS. Insufficient code-signing restrictions allow a local application to bypass security controls and access user-sensitive data. The vulnerability was first addressed in macOS Tahoe 26.3 (released February 11, 2026) and subsequently patched in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, and macOS Tahoe 26.4 (all released March 24, 2026). It carries a CVSS v3.1 base score of 6.2 (Medium), classified under CWE-347 (Improper Verification of Cryptographic Signature) (Apple Advisory 126348, Apple Advisory 126795, Apple Advisory 126796).
The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature), where macOS failed to enforce adequate code-signing restrictions on Intel-based hardware, enabling a downgrade attack. An attacker-controlled application could exploit this weakness to circumvent macOS security controls — specifically within the Spotlight and AppleMobileFileIntegrity subsystems — and gain unauthorized access to user-sensitive data. The attack vector is local (AV:L), requires no privileges (PR:N), and no user interaction (UI:N), making it exploitable by any unprivileged local application on affected Intel-based Macs. The fix involved adding additional code-signing restrictions to prevent the downgrade condition. The vulnerability was discovered and reported by Mickey Jin (@patch1t) (Apple Advisory 126348, Apple Advisory 126794).
Successful exploitation allows a malicious application running locally on an Intel-based Mac to access user-sensitive data without requiring elevated privileges or user interaction. The primary impact is a confidentiality breach (high confidentiality impact per CVSS), as the vulnerability enables unauthorized data access through bypassed code-signing enforcement. There is no integrity or availability impact reported, and the scope is unchanged, limiting the blast radius to the affected system rather than enabling lateral movement (Apple Advisory 126795, Apple Advisory 126796).
Apple has released patches addressing CVE-2026-20699 across all supported macOS versions. Users should update to one of the following patched releases: macOS Sonoma 14.8.5, macOS Sequoia 15.7.5, macOS Tahoe 26.3, or macOS Tahoe 26.4. No configuration-based workarounds have been published; upgrading to a patched version is the only recommended remediation. Note that this vulnerability is specific to Intel-based Mac computers and does not affect Apple Silicon Macs (Apple Advisory 126794, Apple Advisory 126795, Apple Advisory 126796).
The vulnerability was included in Apple's March 2026 security update batch, which addressed over 140 vulnerabilities across macOS, iOS, iPadOS, and tvOS. Security aggregators such as BeyondMachines and the SANS Internet Storm Center noted the breadth of the March 2026 Apple security releases. The CIS (Center for Internet Security) issued an advisory covering multiple vulnerabilities in Apple products from this update cycle, categorizing the overall risk as potentially allowing privilege escalation (SANS ISC, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."