CVE-2026-20661: Use After Free
Accessibility. A privacy issue was addressed by removing sensitive data.
Other sources
Accessibility. An inconsistent user interface issue was addressed with improved state management.
— Apple
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
— MITRE
AppleKeyStore. A use after free issue was addressed with improved memory management.
— Apple
Bluetooth. A denial-of-service issue was addressed with improved validation.
— Apple
Books. A path handling issue was addressed with improved validation.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-20645
- CVE-2026-20674
- CVE-2026-20637
- CVE-2026-20650
- CVE-2026-20638
- CVE-2026-20660
- CVE-2026-20686
- CVE-2026-20611
- CVE-2026-20609
- CVE-2026-20617
- CVE-2026-20615
- CVE-2026-20627
- CVE-2025-14174
- CVE-2025-43529
- CVE-2026-20700
- CVE-2026-20668
- CVE-2026-20649
- CVE-2026-20675
- CVE-2026-20634
- CVE-2026-20654
- CVE-2026-20626
- CVE-2026-20671
- CVE-2026-20663
- CVE-2025-59375
- CVE-2026-20667
- CVE-2026-20655
- CVE-2026-20677
- CVE-2026-20694
- CVE-2026-20642
- CVE-2026-20628
- CVE-2026-20678
- CVE-2026-28855
- CVE-2026-20682
- CVE-2026-20653
- CVE-2026-20680
- CVE-2026-20641
- CVE-2026-20606
- CVE-2026-20640
- CVE-2026-20661
- CVE-2026-20652
- CVE-2026-20608
- CVE-2026-20676
- CVE-2026-20644
- CVE-2026-20636
- CVE-2026-20635
- CVE-2026-20621
- CVE-2025-43537
- CVE-2026-20673
- CVE-2026-20616
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2026-20656
- CVE-2026-20605
Frequently Asked Questions
What is the severity of CVE-2026-20661?
CVE-2026-20661 addresses privacy issues along with inconsistencies in user interface and authorization mechanisms.
How do I fix CVE-2026-20661?
To fix CVE-2026-20661, update your device to iOS version 26.3 or 18.7.5, or iPadOS version 26.3 or 18.7.5.
Which devices are affected by CVE-2026-20661?
CVE-2026-20661 affects Apple iOS and iPadOS devices running versions prior to 26.3 and 18.7.5.
What types of issues does CVE-2026-20661 address?
CVE-2026-20661 addresses privacy concerns, inconsistent user interfaces, and authorization issues.
Is my Apple device vulnerable to CVE-2026-20661?
If your device is running an affected version of iOS or iPadOS prior to the fixes, it is vulnerable to CVE-2026-20661.