Home

Description

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.3, macOS Sonoma 14.8.4, macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An app may be able to access sensitive user data.

PUBLISHED Reserved 2025-11-11 | Published 2026-02-11 | Updated 2026-02-12 | Assigner apple

Problem types

An app may be able to access sensitive user data

Product status

Any version before 26.3
affected

Any version before 26.3
affected

Any version before 15.7
affected

Any version before 14.8
affected

Any version before 26.3
affected

Any version before 18.7
affected

References

support.apple.com/en-us/126348

support.apple.com/en-us/126353

support.apple.com/en-us/126349

support.apple.com/en-us/126350

support.apple.com/en-us/126346

support.apple.com/en-us/126347

cve.org (CVE-2026-20653)

nvd.nist.gov (CVE-2026-20653)

Download JSON