CVE-2026-20657

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. Parsing a maliciously crafted file may lead to an unexpected app termination.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

11 May 2026, 21:18

Type Values Removed Values Added
Summary
  • (es) El problema se abordó con una gestión de memoria mejorada. Este problema está solucionado en iOS 18.7.7 y iPadOS 18.7.7, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5. El análisis de un archivo creado con fines maliciosos puede provocar un cierre inesperado de la aplicación.
Summary (en) The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5. Parsing a maliciously crafted file may lead to an unexpected app termination. (en) A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, visionOS 26.4. Parsing a maliciously crafted file may lead to an unexpected app termination.
References
  • () https://support.apple.com/en-us/126792 -
  • () https://support.apple.com/en-us/126794 -
  • () https://support.apple.com/en-us/126799 -

26 Mar 2026, 17:23

Type Values Removed Values Added
CPE cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
References () https://support.apple.com/en-us/126793 - () https://support.apple.com/en-us/126793 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/126795 - () https://support.apple.com/en-us/126795 - Release Notes, Vendor Advisory
References () https://support.apple.com/en-us/126796 - () https://support.apple.com/en-us/126796 - Release Notes, Vendor Advisory
First Time Apple macos
Apple
Apple iphone Os
Apple ipados

26 Mar 2026, 15:16

Type Values Removed Values Added
CWE CWE-119
CWE-125
CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

25 Mar 2026, 01:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-25 01:17

Updated : 2026-05-11 21:18


NVD link : CVE-2026-20657

Mitre link : CVE-2026-20657

CVE.ORG link : CVE-2026-20657


JSON object : View

Products Affected

apple

  • ipados
  • macos
  • iphone_os
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-125

Out-of-bounds Read

CWE-787

Out-of-bounds Write