CVE-2026-20640

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to iPhone may be able to take and view screenshots of sensitive data from the iPhone during iPhone Mirroring with Mac.
References
Link Resource
https://support.apple.com/en-us/126346 Release Notes Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*

History

17 Feb 2026, 13:30

Type Values Removed Values Added
First Time Apple ipados
Apple
Apple iphone Os
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
References () https://support.apple.com/en-us/126346 - () https://support.apple.com/en-us/126346 - Release Notes, Vendor Advisory

13 Feb 2026, 20:17

Type Values Removed Values Added
CWE CWE-703
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6

11 Feb 2026, 23:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 23:16

Updated : 2026-02-17 13:30


NVD link : CVE-2026-20640

Mitre link : CVE-2026-20640

CVE.ORG link : CVE-2026-20640


JSON object : View

Products Affected

apple

  • iphone_os
  • ipados
CWE
CWE-703

Improper Check or Handling of Exceptional Conditions