A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.3. An app may be able to access sensitive user data.
References
| Link | Resource |
|---|---|
| https://support.apple.com/en-us/126348 | Vendor Advisory |
Configurations
History
12 Feb 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-22 |
12 Feb 2026, 18:29
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | NVD-CWE-noinfo | |
| First Time |
Apple macos
Apple |
|
| CPE | cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| References | () https://support.apple.com/en-us/126348 - Vendor Advisory |
11 Feb 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-11 23:16
Updated : 2026-02-12 20:16
NVD link : CVE-2026-20669
Mitre link : CVE-2026-20669
CVE.ORG link : CVE-2026-20669
JSON object : View
Products Affected
apple
- macos
CWE
NVD-CWE-noinfo
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
