HarborGuard / CVE
Back to search
CRITICALCVE-2026-20677Published Modified CNA apple

CVE-2026-20677: A race condition was addressed with improved handling of symbolic links

A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.

Metrics

CVSS v3.1
9.0
Severity
CRITICAL
Fixed in
14.8.4
Affected Products
3

Fix available

14.8.418.7.526.3
Affected packages
  • Apple / iOS and iPadOS
    < 18.7.5 (from 0) · < 26.3 (from 0)
  • Apple / macOS
    < 14.8.4 (from 0) · < 26.3 (from 0)
  • Apple / visionOS
    < 26.3 (from 0)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H