Home

Description

A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Tahoe 26.3, macOS Sonoma 14.8.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. A shortcut may be able to bypass sandbox restrictions.

PUBLISHED Reserved 2025-11-11 | Published 2026-02-11 | Updated 2026-02-17 | Assigner apple

Problem types

A shortcut may be able to bypass sandbox restrictions

Product status

Any version before 26.3
affected

Any version before 26.3
affected

Any version before 14.8
affected

Any version before 26.3
affected

Any version before 18.7
affected

References

support.apple.com/en-us/126348

support.apple.com/en-us/126353

support.apple.com/en-us/126350

support.apple.com/en-us/126346

support.apple.com/en-us/126347

cve.org (CVE-2026-20677)

nvd.nist.gov (CVE-2026-20677)

Download JSON