CVE-2026-20677CRITICAL 9.0EPSS p17.6%

CVE-2026-20677CVE-2026-20677

Description

A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.

Scoring

CVSS 3.19.0 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS0.26% probability of exploitation · percentile 17.6% · 2026-06-18T12:00:27Z
Published2026-02-11
Last modified2026-04-02

Underlying weaknesses· 2

CWE-362CWE-367

References

  1. https://support.apple.com/en-us/126346
  2. https://support.apple.com/en-us/126347
  3. https://support.apple.com/en-us/126348
  4. https://support.apple.com/en-us/126350
  5. https://support.apple.com/en-us/126353

2

TypeTargetConfidenceTier
WeaknessConcurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')cwe-3620%live
WeaknessTime-of-check Time-of-use (TOCTOU) Race Conditioncwe-3670%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-43358
CVE
CVE-2026-20688
CVE
CVE-2026-20667
CVE
CVE-2025-30465
CVE
CVE-2026-28827
CVE
CVE-2025-30433
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.