CVE-2026-20658: Input Validation
A package validation issue was addressed by blocking the vulnerable package. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges.
Other sources
Admin Framework. A parsing issue in the handling of directory paths was addressed with improved path validation.
— Apple
AppleEvents. An authorization issue was addressed with improved state management.
— Apple
AppleKeyStore. A use after free issue was addressed with improved memory management.
— Apple
AppleMobileFileIntegrity. A parsing issue in the handling of directory paths was addressed with improved path validation.
— Apple
AppleMobileFileIntegrity. An injection issue was addressed with improved validation.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-20669
- CVE-2026-20670
- CVE-2026-20637
- CVE-2026-20625
- CVE-2026-20624
- CVE-2026-20650
- CVE-2026-20660
- CVE-2026-20639
- CVE-2026-20681
- CVE-2026-20611
- CVE-2026-20609
- CVE-2026-20617
- CVE-2026-20615
- CVE-2026-20627
- CVE-2025-14174
- CVE-2025-43529
- CVE-2026-20700
- CVE-2026-20668
- CVE-2026-20629
- CVE-2026-20601
- CVE-2026-20623
- CVE-2026-20649
- CVE-2026-20620
- CVE-2026-20675
- CVE-2026-20634
- CVE-2026-20654
- CVE-2026-20626
- CVE-2026-20671
- CVE-2026-20630
- CVE-2025-59375
- CVE-2026-20667
- CVE-2026-20673
- CVE-2026-20677
- CVE-2026-20651
- CVE-2026-20694
- CVE-2026-20616
- CVE-2026-20603
- CVE-2026-20666
- CVE-2026-20614
- CVE-2026-20656
- CVE-2026-20628
- CVE-2026-28855
- CVE-2026-20658
- CVE-2026-20610
- CVE-2026-20653
- CVE-2026-20622
- CVE-2026-20648
- CVE-2026-20662
- CVE-2026-20647
- CVE-2026-20680
- CVE-2026-20612
- CVE-2026-20699
- CVE-2026-20641
- CVE-2026-20619
- CVE-2026-20618
- CVE-2026-20606
- CVE-2026-20605
- CVE-2026-20646
- CVE-2026-20652
- CVE-2026-20608
- CVE-2026-20676
- CVE-2026-20644
- CVE-2026-20636
- CVE-2026-20635
- CVE-2026-20621
- CVE-2026-20602
Frequently Asked Questions
What is the severity of CVE-2026-20658?
The severity of CVE-2026-20658 is considered high due to the potential for an application to gain root privileges.
How do I fix CVE-2026-20658?
To fix CVE-2026-20658, update your system to macOS Tahoe version 26.3 or later.
What type of issue is described by CVE-2026-20658?
CVE-2026-20658 describes a package validation issue and parsing problem in the handling of directory paths.
Which versions of macOS are affected by CVE-2026-20658?
Versions of macOS Tahoe prior to 26.3 are affected by CVE-2026-20658.
What can occur due to the vulnerability in CVE-2026-20658?
Due to the vulnerability in CVE-2026-20658, an app may be able to gain elevated privileges, posing a significant security risk.