CVE-2026-20620: Input Validation
Admin Framework. A parsing issue in the handling of directory paths was addressed with improved path validation.
Other sources
An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. An attacker may be able to cause unexpected system termination or read kernel memory.
— MITRE
AppleEvents. An authorization issue was addressed with improved state management.
— Apple
AppleKeyStore. A use after free issue was addressed with improved memory management.
— Apple
AppleMobileFileIntegrity. A parsing issue in the handling of directory paths was addressed with improved path validation.
— Apple
AppleMobileFileIntegrity. An injection issue was addressed with improved validation.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-20670
- CVE-2026-20624
- CVE-2026-20625
- CVE-2026-20660
- CVE-2025-43403
- CVE-2026-20611
- CVE-2026-20609
- CVE-2026-20617
- CVE-2026-20615
- CVE-2025-46283
- CVE-2026-20627
- CVE-2025-43417
- CVE-2026-20620
- CVE-2025-43338
- CVE-2026-20634
- CVE-2026-20675
- CVE-2026-20671
- CVE-2025-59375
- CVE-2026-20667
- CVE-2026-20673
- CVE-2026-20677
- CVE-2026-20651
- CVE-2026-20694
- CVE-2026-20616
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2025-46310
- CVE-2026-20614
- CVE-2026-20628
- CVE-2025-46290
- CVE-2026-20653
- CVE-2026-20680
- CVE-2026-20612
- CVE-2026-20641
- CVE-2026-20606
- CVE-2026-20605
- CVE-2026-20621
- CVE-2025-43402
- CVE-2026-20602
- CVE-2026-20626
- CVE-2026-20622
- CVE-2026-20662
- CVE-2026-20619
- CVE-2026-20669
- CVE-2026-20637
- CVE-2026-20650
- CVE-2026-20639
- CVE-2026-20681
- CVE-2025-14174
- CVE-2025-43529
- CVE-2026-20700
- CVE-2026-20668
- CVE-2026-20629
- CVE-2026-20601
- CVE-2026-20623
- CVE-2026-20649
- CVE-2026-20654
- CVE-2026-20630
- CVE-2026-20603
- CVE-2026-20666
- CVE-2026-20656
- CVE-2026-28855
- CVE-2026-20658
- CVE-2026-20610
- CVE-2026-20648
- CVE-2026-20647
- CVE-2026-20699
- CVE-2026-20618
- CVE-2026-20646
- CVE-2026-20652
- CVE-2026-20608
- CVE-2026-20676
- CVE-2026-20644
- CVE-2026-20636
- CVE-2026-20635
Frequently Asked Questions
What is the severity of CVE-2026-20620?
CVE-2026-20620 has been rated as a critical vulnerability affecting directory path parsing in certain macOS versions.
How do I fix CVE-2026-20620?
To fix CVE-2026-20620, you should upgrade to macOS Sequoia 15.7.4, macOS Tahoe 26.3, or macOS Sonoma 14.8.4.
Which versions of macOS are affected by CVE-2026-20620?
CVE-2026-20620 affects macOS Sequoia versions prior to 15.7.4, macOS Tahoe versions prior to 26.3, and macOS Sonoma versions prior to 14.8.4.
What is the nature of the vulnerability in CVE-2026-20620?
CVE-2026-20620 involves a parsing issue that can lead to an out-of-bounds read due to improper input handling.
Can CVE-2026-20620 be exploited remotely?
Yes, an attacker could potentially exploit CVE-2026-20620 remotely by sending specifically crafted inputs to the affected system.