CVE-2026-20662: Infoleak
Admin Framework. A parsing issue in the handling of directory paths was addressed with improved path validation.
Other sources
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An attacker with physical access to a locked device may be able to view sensitive user information.
— NVD
AppleEvents. An authorization issue was addressed with improved state management.
— Apple
AppleKeyStore. A use after free issue was addressed with improved memory management.
— Apple
AppleMobileFileIntegrity. A parsing issue in the handling of directory paths was addressed with improved path validation.
— Apple
AppleMobileFileIntegrity. An injection issue was addressed with improved validation.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-20624
- CVE-2026-20625
- CVE-2025-43403
- CVE-2026-20611
- CVE-2026-20609
- CVE-2026-20620
- CVE-2026-20634
- CVE-2026-20675
- CVE-2026-20671
- CVE-2026-20626
- CVE-2025-59375
- CVE-2026-20667
- CVE-2026-20673
- CVE-2026-20694
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2025-46310
- CVE-2026-20614
- CVE-2026-20628
- CVE-2025-46290
- CVE-2026-20653
- CVE-2026-20622
- CVE-2026-20662
- CVE-2026-20680
- CVE-2026-20612
- CVE-2026-20641
- CVE-2026-20619
- CVE-2026-20606
- CVE-2026-20605
- CVE-2026-20621
- CVE-2025-43402
- CVE-2026-20602
- CVE-2026-20669
- CVE-2026-20670
- CVE-2026-20637
- CVE-2026-20650
- CVE-2026-20660
- CVE-2026-20639
- CVE-2026-20681
- CVE-2026-20617
- CVE-2026-20615
- CVE-2026-20627
- CVE-2025-14174
- CVE-2025-43529
- CVE-2026-20700
- CVE-2026-20668
- CVE-2026-20629
- CVE-2026-20601
- CVE-2026-20623
- CVE-2026-20649
- CVE-2026-20654
- CVE-2026-20630
- CVE-2026-20677
- CVE-2026-20651
- CVE-2026-20616
- CVE-2026-20603
- CVE-2026-20666
- CVE-2026-20656
- CVE-2026-28855
- CVE-2026-20658
- CVE-2026-20610
- CVE-2026-20648
- CVE-2026-20647
- CVE-2026-20699
- CVE-2026-20618
- CVE-2026-20646
- CVE-2026-20652
- CVE-2026-20608
- CVE-2026-20676
- CVE-2026-20644
- CVE-2026-20636
- CVE-2026-20635
Frequently Asked Questions
What is the severity of CVE-2026-20662?
CVE-2026-20662 has a high severity rating due to its potential for exploitation by attackers with physical access to a locked device.
How do I fix CVE-2026-20662?
To fix CVE-2026-20662, update your device to macOS Sequoia 15.7.4 or macOS Tahoe 26.3.
What type of vulnerability is CVE-2026-20662?
CVE-2026-20662 is a security vulnerability related to directory path parsing and authorization issues.
Who is affected by CVE-2026-20662?
Users of macOS Sequoia versions below 15.7.4 and macOS Tahoe versions below 26.3 are affected by CVE-2026-20662.
What impact does CVE-2026-20662 have on security?
CVE-2026-20662 can potentially allow an attacker to bypass authorization and gain access to sensitive data on a locked device.