
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20700 is a memory corruption vulnerability in Apple's dynamic linker (dyld) that allows an attacker with local memory write capability to execute arbitrary code. Discovered and reported by Google Threat Analysis Group, it was disclosed and patched on February 11, 2026. The vulnerability affects iOS, iPadOS, macOS, watchOS, tvOS, and visionOS versions prior to 26.3. Apple confirmed active exploitation in "an extremely sophisticated attack against specific targeted individuals" on versions of iOS before iOS 26. It carries a CVSS v3.1 base score of 7.8 (High) (Apple iOS Advisory, Apple tvOS Advisory).
The vulnerability is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and resides in Apple's dyld (dynamic linker), a core system component present since iOS 1.0. The root cause is a memory corruption issue stemming from improper state management, which Apple addressed with improved state management in the patched releases. An attacker who has already obtained memory write capability — for example, through a prior stage in an exploit chain — can leverage this flaw to achieve arbitrary code execution. CVE-2026-20700 was part of a multi-stage exploit chain alongside CVE-2025-14174 and CVE-2025-43529, all issued in response to the same targeted attack report. A PoC was published on GitHub shortly after disclosure, and technical analysis of the dyld commit fixing the issue was discussed publicly (Apple iOS Advisory, Apple watchOS Advisory, Feedly).
Successful exploitation allows an attacker with existing memory write access to execute arbitrary code with elevated privileges on the affected device, resulting in full confidentiality, integrity, and availability compromise. The vulnerability has been weaponized in real-world attacks through the DarkSword iOS exploit kit (a six-vulnerability chain including three zero-days) and the Coruna malware, enabling infostealer payloads capable of exfiltrating personal data, credentials, and cryptocurrency wallet contents. The broad scope of affected platforms — iOS, iPadOS, macOS, watchOS, tvOS, and visionOS — means the attack surface spans hundreds of millions of devices, and the exploit chain's adoption by multiple threat actors (including state-sponsored groups) significantly amplifies the risk of lateral movement and data exposure (Google Cloud Blog, BleepingComputer DarkSword, Feedly).
dyld component.dyld by abusing improper state management, converting the memory write primitive into arbitrary code execution at a higher privilege level.dyld or memory corruption errors on iOS/macOS; sysdiagnose logs showing unusual process spawning from browser or system processes.Apple released patches on February 11, 2026 for all affected platforms. Users should immediately update to iOS 26.3, iPadOS 26.3, macOS Tahoe 26.3, watchOS 26.3, tvOS 26.3, or visionOS 26.3 or later. Apple subsequently expanded iOS 18 security updates to older iPhone models to block DarkSword attacks, so users on legacy devices should also apply available updates. CISA ordered federal agencies to patch by the KEV catalog deadline. No configuration-based workaround is available; patching is the only remediation. Organizations managing Apple device fleets should prioritize immediate patch deployment and use MDM solutions to enforce compliance (Apple iOS Advisory, Apple macOS Advisory, CISA KEV, BleepingComputer iOS 18).
Apple's advisory explicitly acknowledged active exploitation in "an extremely sophisticated attack against specific targeted individuals," an unusually direct disclosure that drew significant media attention (Apple iOS Advisory). Google Threat Analysis Group was credited with discovering and reporting the vulnerability, and subsequently published detailed research on the DarkSword exploit chain that incorporated CVE-2026-20700 (Google Cloud Blog). Security researchers and media outlets including BleepingComputer, The Hacker News, Security Affairs, and Forbes covered the vulnerability extensively, with many noting that the underlying dyld bug had reportedly existed since iOS 1.0 — earning it the informal label of a "forever-day" vulnerability (BleepingComputer DarkSword, Feedly). Community discussion on Reddit and Hacker News was active, with defenders urging immediate patching and researchers analyzing the dyld commit that introduced the fix.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."