CVE-2026-20700
macOS vulnerability analysis and mitigation

Overview

CVE-2026-20700 is a memory corruption vulnerability in Apple's dynamic linker (dyld) that allows an attacker with local memory write capability to execute arbitrary code. Discovered and reported by Google Threat Analysis Group, it was disclosed and patched on February 11, 2026. The vulnerability affects iOS, iPadOS, macOS, watchOS, tvOS, and visionOS versions prior to 26.3. Apple confirmed active exploitation in "an extremely sophisticated attack against specific targeted individuals" on versions of iOS before iOS 26. It carries a CVSS v3.1 base score of 7.8 (High) (Apple iOS Advisory, Apple tvOS Advisory).

Technical details

The vulnerability is classified as CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and resides in Apple's dyld (dynamic linker), a core system component present since iOS 1.0. The root cause is a memory corruption issue stemming from improper state management, which Apple addressed with improved state management in the patched releases. An attacker who has already obtained memory write capability — for example, through a prior stage in an exploit chain — can leverage this flaw to achieve arbitrary code execution. CVE-2026-20700 was part of a multi-stage exploit chain alongside CVE-2025-14174 and CVE-2025-43529, all issued in response to the same targeted attack report. A PoC was published on GitHub shortly after disclosure, and technical analysis of the dyld commit fixing the issue was discussed publicly (Apple iOS Advisory, Apple watchOS Advisory, Feedly).

Impact

Successful exploitation allows an attacker with existing memory write access to execute arbitrary code with elevated privileges on the affected device, resulting in full confidentiality, integrity, and availability compromise. The vulnerability has been weaponized in real-world attacks through the DarkSword iOS exploit kit (a six-vulnerability chain including three zero-days) and the Coruna malware, enabling infostealer payloads capable of exfiltrating personal data, credentials, and cryptocurrency wallet contents. The broad scope of affected platforms — iOS, iPadOS, macOS, watchOS, tvOS, and visionOS — means the attack surface spans hundreds of millions of devices, and the exploit chain's adoption by multiple threat actors (including state-sponsored groups) significantly amplifies the risk of lateral movement and data exposure (Google Cloud Blog, BleepingComputer DarkSword, Feedly).

Exploitation steps

  1. Initial Access via Browser Exploit: The DarkSword exploit chain begins with a drive-by attack. The attacker lures the target to a malicious or compromised website, where a JavaScript-based exploit (leveraging CVE-2025-43529, a WebKit vulnerability) is delivered to gain initial code execution within the browser sandbox.
  2. Sandbox Escape: Using CVE-2025-14174 (a related zero-day issued alongside CVE-2026-20700), the attacker escapes the browser sandbox to gain broader process-level access on the device.
  3. Memory Write Primitive Establishment: With out-of-sandbox access, the attacker establishes a memory write primitive, satisfying the precondition required to exploit CVE-2026-20700 in the dyld component.
  4. dyld Memory Corruption Exploitation: The attacker triggers the memory corruption bug in dyld by abusing improper state management, converting the memory write primitive into arbitrary code execution at a higher privilege level.
  5. Payload Delivery: With arbitrary code execution achieved, the attacker deploys an infostealer payload (e.g., Coruna or GHOSTBLADE malware) capable of exfiltrating contacts, messages, photos, credentials, and cryptocurrency wallet data.
  6. Persistence and Exfiltration: The malware establishes persistence and exfiltrates collected data to attacker-controlled infrastructure (Google Cloud Blog, Lookout, Apple iOS Advisory).

Indicators of compromise

  • Network: Outbound connections from iOS/macOS devices to unknown or suspicious IP addresses following web browsing activity; unusual DNS queries to domains associated with DarkSword C2 infrastructure; unexpected data exfiltration traffic (large outbound transfers).
  • Device Behavior: Unexpected battery drain, device overheating, or sluggish performance on unpatched devices; apps crashing unexpectedly, particularly Safari or WebKit-based apps.
  • Logs: Crash logs referencing dyld or memory corruption errors on iOS/macOS; sysdiagnose logs showing unusual process spawning from browser or system processes.
  • File System: Presence of unknown or unsigned binaries in app containers or temporary directories; unexpected configuration profile installations.
  • Threat Intelligence: Device identifiers (UDID, IP) appearing in DarkSword or Coruna campaign IOC feeds published by Lookout and Google Threat Analysis Group (Google Cloud Blog, Lookout).

Mitigation and workarounds

Apple released patches on February 11, 2026 for all affected platforms. Users should immediately update to iOS 26.3, iPadOS 26.3, macOS Tahoe 26.3, watchOS 26.3, tvOS 26.3, or visionOS 26.3 or later. Apple subsequently expanded iOS 18 security updates to older iPhone models to block DarkSword attacks, so users on legacy devices should also apply available updates. CISA ordered federal agencies to patch by the KEV catalog deadline. No configuration-based workaround is available; patching is the only remediation. Organizations managing Apple device fleets should prioritize immediate patch deployment and use MDM solutions to enforce compliance (Apple iOS Advisory, Apple macOS Advisory, CISA KEV, BleepingComputer iOS 18).

Community reactions

Apple's advisory explicitly acknowledged active exploitation in "an extremely sophisticated attack against specific targeted individuals," an unusually direct disclosure that drew significant media attention (Apple iOS Advisory). Google Threat Analysis Group was credited with discovering and reporting the vulnerability, and subsequently published detailed research on the DarkSword exploit chain that incorporated CVE-2026-20700 (Google Cloud Blog). Security researchers and media outlets including BleepingComputer, The Hacker News, Security Affairs, and Forbes covered the vulnerability extensively, with many noting that the underlying dyld bug had reportedly existed since iOS 1.0 — earning it the informal label of a "forever-day" vulnerability (BleepingComputer DarkSword, Feedly). Community discussion on Reddit and Hacker News was active, with defenders urging immediate patching and researchers analyzing the dyld commit that introduced the fix.

Additional resources


SourceThis report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-43746MEDIUM6.5
  • Apple Safari logoApple Safari
  • cpe:2.3:a:apple:safari
NoYesJun 29, 2026
CVE-2026-43745MEDIUM6.5
  • Apple Safari logoApple Safari
  • pywebkitgtk
NoYesJun 29, 2026
CVE-2026-43742MEDIUM6.5
  • Apple Safari logoApple Safari
  • wpewebkit
NoYesJun 29, 2026
CVE-2026-43740MEDIUM6.5
  • Apple Safari logoApple Safari
  • webkit2gtk3-jsc-devel
NoYesJun 29, 2026
CVE-2026-43743MEDIUM4.7
  • macOS logomacOS
  • IOGPUFamily
NoYesJun 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management