CVE-2026-20640: Use After Free
Accessibility. A privacy issue was addressed by removing sensitive data.
Other sources
Accessibility. An inconsistent user interface issue was addressed with improved state management.
— Apple
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3. An attacker with physical access to iPhone may be able to take and view screenshots of sensitive data from the iPhone during iPhone Mirroring with Mac.
— MITRE
AppleKeyStore. A use after free issue was addressed with improved memory management.
— Apple
Bluetooth. A denial-of-service issue was addressed with improved validation.
— Apple
Call History. A logic issue was addressed with improved checks.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-20645
- CVE-2026-20674
- CVE-2026-20637
- CVE-2026-20650
- CVE-2026-20638
- CVE-2026-20660
- CVE-2026-20686
- CVE-2026-20611
- CVE-2026-20609
- CVE-2026-20617
- CVE-2026-20615
- CVE-2026-20627
- CVE-2025-14174
- CVE-2025-43529
- CVE-2026-20700
- CVE-2026-20668
- CVE-2026-20649
- CVE-2026-20675
- CVE-2026-20634
- CVE-2026-20654
- CVE-2026-20626
- CVE-2026-20671
- CVE-2026-20663
- CVE-2025-59375
- CVE-2026-20667
- CVE-2026-20655
- CVE-2026-20677
- CVE-2026-20694
- CVE-2026-20642
- CVE-2026-20628
- CVE-2026-20678
- CVE-2026-28855
- CVE-2026-20682
- CVE-2026-20653
- CVE-2026-20680
- CVE-2026-20641
- CVE-2026-20606
- CVE-2026-20640
- CVE-2026-20661
- CVE-2026-20652
- CVE-2026-20608
- CVE-2026-20676
- CVE-2026-20644
- CVE-2026-20636
- CVE-2026-20635
- CVE-2026-20621
Frequently Asked Questions
What is the severity of CVE-2026-20640?
CVE-2026-20640 has been identified as a privacy issue that affects the user interface and security of Apple iOS and iPadOS.
How do I fix CVE-2026-20640?
To fix CVE-2026-20640, update your device to iOS 26.3 or iPadOS 26.3.
What types of devices are affected by CVE-2026-20640?
CVE-2026-20640 affects Apple devices running iOS and iPadOS versions prior to 26.3.
What are the main issues addressed in CVE-2026-20640?
CVE-2026-20640 addresses a privacy issue by removing sensitive data and improves inconsistent user interface state management.
Is there a workaround for CVE-2026-20640 until I can update?
There is no known workaround for CVE-2026-20640, so updating to the latest version is recommended.