CVE-2026-20678: Infoleak
Accessibility. A privacy issue was addressed by removing sensitive data.
Other sources
Accessibility. An inconsistent user interface issue was addressed with improved state management.
— Apple
An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user data.
— MITRE
AppleKeyStore. A use after free issue was addressed with improved memory management.
— Apple
Bluetooth. A denial-of-service issue was addressed with improved validation.
— Apple
Books. A path handling issue was addressed with improved validation.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-20645
- CVE-2026-20674
- CVE-2026-20637
- CVE-2026-20650
- CVE-2026-20638
- CVE-2026-20660
- CVE-2026-20686
- CVE-2026-20611
- CVE-2026-20609
- CVE-2026-20617
- CVE-2026-20615
- CVE-2026-20627
- CVE-2025-14174
- CVE-2025-43529
- CVE-2026-20700
- CVE-2026-20668
- CVE-2026-20649
- CVE-2026-20675
- CVE-2026-20634
- CVE-2026-20654
- CVE-2026-20626
- CVE-2026-20671
- CVE-2026-20663
- CVE-2025-59375
- CVE-2026-20667
- CVE-2026-20655
- CVE-2026-20677
- CVE-2026-20694
- CVE-2026-20642
- CVE-2026-20628
- CVE-2026-20678
- CVE-2026-28855
- CVE-2026-20682
- CVE-2026-20653
- CVE-2026-20680
- CVE-2026-20641
- CVE-2026-20606
- CVE-2026-20640
- CVE-2026-20661
- CVE-2026-20652
- CVE-2026-20608
- CVE-2026-20676
- CVE-2026-20644
- CVE-2026-20636
- CVE-2026-20635
- CVE-2026-20621
- CVE-2025-43537
- CVE-2026-20673
- CVE-2026-20616
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2026-20656
- CVE-2026-20605
Frequently Asked Questions
What is the severity of CVE-2026-20678?
CVE-2026-20678 is considered a privacy and authorization issue that requires immediate attention due to its potential impact.
How do I fix CVE-2026-20678?
To fix CVE-2026-20678, update to iOS or iPadOS versions 26.3 or 18.7.5.
What versions are affected by CVE-2026-20678?
CVE-2026-20678 affects iOS versions prior to 26.3 and 18.7.5, as well as corresponding iPadOS versions.
What types of issues does CVE-2026-20678 address?
CVE-2026-20678 addresses privacy concerns, inconsistent user interface experiences, and authorization issues.
Is there a specific mitigation available for CVE-2026-20678?
The only mitigation for CVE-2026-20678 is to upgrade to the latest recommended software versions.