CVE-2026-20655: Use After Free
Accessibility. A privacy issue was addressed by removing sensitive data.
Other sources
Accessibility. An inconsistent user interface issue was addressed with improved state management.
— Apple
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
— MITRE
AppleKeyStore. A use after free issue was addressed with improved memory management.
— Apple
Bluetooth. A denial-of-service issue was addressed with improved validation.
— Apple
Books. A path handling issue was addressed with improved validation.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-20645
- CVE-2026-20674
- CVE-2026-20637
- CVE-2026-20650
- CVE-2026-20638
- CVE-2026-20660
- CVE-2026-20686
- CVE-2026-20611
- CVE-2026-20609
- CVE-2026-20617
- CVE-2026-20615
- CVE-2026-20627
- CVE-2025-14174
- CVE-2025-43529
- CVE-2026-20700
- CVE-2026-20668
- CVE-2026-20649
- CVE-2026-20675
- CVE-2026-20634
- CVE-2026-20654
- CVE-2026-20626
- CVE-2026-20671
- CVE-2026-20663
- CVE-2025-59375
- CVE-2026-20667
- CVE-2026-20655
- CVE-2026-20677
- CVE-2026-20694
- CVE-2026-20642
- CVE-2026-20628
- CVE-2026-20678
- CVE-2026-28855
- CVE-2026-20682
- CVE-2026-20653
- CVE-2026-20680
- CVE-2026-20641
- CVE-2026-20606
- CVE-2026-20640
- CVE-2026-20661
- CVE-2026-20652
- CVE-2026-20608
- CVE-2026-20676
- CVE-2026-20644
- CVE-2026-20636
- CVE-2026-20635
- CVE-2026-20621
- CVE-2025-43537
- CVE-2026-20673
- CVE-2026-20616
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2026-20656
- CVE-2026-20605
Frequently Asked Questions
What is the severity of CVE-2026-20655?
CVE-2026-20655 is classified as a privacy and authorization issue affecting multiple versions of iOS and iPadOS.
How do I fix CVE-2026-20655?
To mitigate CVE-2026-20655, upgrade your device to iOS 26.3 or iPadOS 26.3, or to iOS 18.7.5 or iPadOS 18.7.5.
What types of issues does CVE-2026-20655 address?
CVE-2026-20655 addresses privacy, inconsistent user interface, and authorization issues through improved state management.
Which Apple products are affected by CVE-2026-20655?
CVE-2026-20655 affects Apple devices running specific earlier versions of iOS and iPadOS up to 26.3 and 18.7.5.
When was CVE-2026-20655 reported?
CVE-2026-20655 was reported as part of updates made to enhance security and user interface in Apple's software.