VYPR
Medium severity5.5NVD Advisory· Published Feb 11, 2026· Updated Apr 2, 2026

CVE-2026-20653

CVE-2026-20653

Description

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A path parsing vulnerability in Apple OS components could allow an app to access sensitive user data. Patched February 2026.

Root

Cause A parsing issue in the handling of directory paths was addressed with improved path validation on multiple Apple platforms [1]. The vulnerability stems from improper path validation, which could allow an application to traverse or access unintended directories.

Exploitation

An app with the ability to issue path operations could exploit the flaw without requiring elevated privileges beyond normal app sandbox restrictions. The attack surface is local, meaning an attacker would need to have a malicious app installed on the device or gain code execution within an existing app [1][2].

Impact

Successful exploitation could allow the app to access sensitive user data that it would otherwise be restricted from reading, such as documents, cookies, or other protected files [1]. The vulnerability is rated Medium with a CVSS v3 score of 5.5, indicating a moderate risk to confidentiality.

Mitigation

Apple released fixes on February 11, 2026, for iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, and visionOS 26.3 [1][2]. Users should update to the latest available OS version to remediate the issue.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

7

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.