CVE-2026-20673: Race Condition
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. Turning off "Load remote content in messages” may not apply to all mail previews.
Other sources
Accessibility. An inconsistent user interface issue was addressed with improved state management.
— Apple
Admin Framework. A parsing issue in the handling of directory paths was addressed with improved path validation.
— Apple
AppleEvents. An authorization issue was addressed with improved state management.
— Apple
AppleKeyStore. A use after free issue was addressed with improved memory management.
— Apple
AppleMobileFileIntegrity. A parsing issue in the handling of directory paths was addressed with improved path validation.
— Apple
Credit
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-20645
- CVE-2025-43537
- CVE-2026-20660
- CVE-2026-20611
- CVE-2026-20609
- CVE-2026-20634
- CVE-2026-20675
- CVE-2026-20671
- CVE-2026-20663
- CVE-2025-59375
- CVE-2026-20655
- CVE-2026-20673
- CVE-2026-20677
- CVE-2026-20616
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2026-20656
- CVE-2026-20628
- CVE-2026-20678
- CVE-2026-20682
- CVE-2026-20653
- CVE-2026-20680
- CVE-2026-20641
- CVE-2026-20606
- CVE-2026-20605
- CVE-2026-20661
- CVE-2026-20608
- CVE-2026-20652
- CVE-2026-20644
- CVE-2026-20635
- CVE-2026-20621
- CVE-2026-20670
- CVE-2026-20624
- CVE-2026-20625
- CVE-2025-43403
- CVE-2026-20617
- CVE-2026-20615
- CVE-2025-46283
- CVE-2026-20627
- CVE-2025-43417
- CVE-2026-20620
- CVE-2025-43338
- CVE-2026-20667
- CVE-2026-20651
- CVE-2026-20694
- CVE-2025-46310
- CVE-2026-20614
- CVE-2025-46290
- CVE-2026-20612
- CVE-2025-43402
- CVE-2026-20602
- CVE-2026-20626
- CVE-2026-20622
- CVE-2026-20662
- CVE-2026-20619
- CVE-2026-20669
- CVE-2026-20637
- CVE-2026-20650
- CVE-2026-20639
- CVE-2026-20681
- CVE-2025-14174
- CVE-2025-43529
- CVE-2026-20700
- CVE-2026-20668
- CVE-2026-20629
- CVE-2026-20601
- CVE-2026-20623
- CVE-2026-20649
- CVE-2026-20654
- CVE-2026-20630
- CVE-2026-20603
- CVE-2026-20666
- CVE-2026-28855
- CVE-2026-20658
- CVE-2026-20610
- CVE-2026-20648
- CVE-2026-20647
- CVE-2026-20699
- CVE-2026-20618
- CVE-2026-20646
- CVE-2026-20676
- CVE-2026-20636
Frequently Asked Questions
What is the severity of CVE-2026-20673?
CVE-2026-20673 has been classified with a high severity due to its potential impact on user data and device security.
How do I fix CVE-2026-20673?
To fix CVE-2026-20673, update your device to the latest version of macOS Sequoia 15.7.4, macOS Tahoe 26.3, macOS Sonoma 14.8.4, iOS 18.7.5, or iPadOS 18.7.5.
What devices are affected by CVE-2026-20673?
CVE-2026-20673 affects Apple devices running macOS Sequoia, macOS Tahoe, macOS Sonoma, iOS, and iPadOS prior to their respective latest versions.
What type of issue is CVE-2026-20673?
CVE-2026-20673 is classified as a logic issue that could lead to inconsistent user interface behavior.
Is there a workaround for CVE-2026-20673 before applying the fix?
A temporary workaround for CVE-2026-20673 is to disable 'Load remote content in messages,' but this may not fully mitigate the vulnerability.