CVE-2026-20653
Description
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. An app may be able to access sensitive user data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A path parsing vulnerability in Apple OS components could allow an app to access sensitive user data. Patched February 2026.
Root
Cause A parsing issue in the handling of directory paths was addressed with improved path validation on multiple Apple platforms [1]. The vulnerability stems from improper path validation, which could allow an application to traverse or access unintended directories.
Exploitation
An app with the ability to issue path operations could exploit the flaw without requiring elevated privileges beyond normal app sandbox restrictions. The attack surface is local, meaning an attacker would need to have a malicious app installed on the device or gain code execution within an existing app [1][2].
Impact
Successful exploitation could allow the app to access sensitive user data that it would otherwise be restricted from reading, such as documents, cookies, or other protected files [1]. The vulnerability is rated Medium with a CVSS v3 score of 5.5, indicating a moderate risk to confidentiality.
Mitigation
Apple released fixes on February 11, 2026, for iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, and visionOS 26.3 [1][2]. Users should update to the latest available OS version to remediate the issue.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
7cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*range: <18.7.5
- (no CPE)range: 18.7.5, 26.3
- Range: 18.7.5, 26.3
- Range: 15.7.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- support.apple.com/en-us/126346nvdRelease NotesVendor Advisory
- support.apple.com/en-us/126347nvdRelease NotesVendor Advisory
- support.apple.com/en-us/126348nvdRelease NotesVendor Advisory
- support.apple.com/en-us/126349nvdRelease NotesVendor Advisory
- support.apple.com/en-us/126350nvdRelease NotesVendor Advisory
- support.apple.com/en-us/126353nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.