CVE-2026-20682: Infoleak
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3. An attacker may be able to discover a user’s deleted notes.
Other sources
Accessibility. A privacy issue was addressed by removing sensitive data.
— Apple
Accessibility. An inconsistent user interface issue was addressed with improved state management.
— Apple
AppleKeyStore. A use after free issue was addressed with improved memory management.
— Apple
Bluetooth. A denial-of-service issue was addressed with improved validation.
— Apple
Books. A path handling issue was addressed with improved validation.
— Apple
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-20645
- CVE-2026-20674
- CVE-2026-20637
- CVE-2026-20650
- CVE-2026-20638
- CVE-2026-20660
- CVE-2026-20686
- CVE-2026-20611
- CVE-2026-20609
- CVE-2026-20617
- CVE-2026-20615
- CVE-2026-20627
- CVE-2025-14174
- CVE-2025-43529
- CVE-2026-20700
- CVE-2026-20668
- CVE-2026-20649
- CVE-2026-20675
- CVE-2026-20634
- CVE-2026-20654
- CVE-2026-20626
- CVE-2026-20671
- CVE-2026-20663
- CVE-2025-59375
- CVE-2026-20667
- CVE-2026-20655
- CVE-2026-20677
- CVE-2026-20694
- CVE-2026-20642
- CVE-2026-20628
- CVE-2026-20678
- CVE-2026-28855
- CVE-2026-20682
- CVE-2026-20653
- CVE-2026-20680
- CVE-2026-20641
- CVE-2026-20606
- CVE-2026-20640
- CVE-2026-20661
- CVE-2026-20652
- CVE-2026-20608
- CVE-2026-20676
- CVE-2026-20644
- CVE-2026-20636
- CVE-2026-20635
- CVE-2026-20621
- CVE-2025-43537
- CVE-2026-20673
- CVE-2026-20616
- CVE-2025-43533
- CVE-2025-46300
- CVE-2025-46301
- CVE-2025-46302
- CVE-2025-46303
- CVE-2025-46304
- CVE-2025-46305
- CVE-2026-20656
- CVE-2026-20605
Frequently Asked Questions
What is the severity of CVE-2026-20682?
The severity of CVE-2026-20682 is high due to the potential for unauthorized access to deleted notes.
How do I fix CVE-2026-20682?
To fix CVE-2026-20682, update your device to iOS 26.3 or iPadOS 26.3, or to iOS 18.7.5 or iPadOS 18.7.5.
What devices are affected by CVE-2026-20682?
CVE-2026-20682 affects Apple devices running iOS versions below 26.3 and 18.7.5, as well as iPadOS versions below 26.3 and 18.7.5.
What kind of data can be exposed in CVE-2026-20682?
CVE-2026-20682 can potentially expose deleted notes and sensitive data due to a logic issue.
Is there a workaround for CVE-2026-20682?
There is no specific workaround for CVE-2026-20682; updating to the latest software version is recommended.