CVE-2026-20638 PUBLISHED

Assigner: apple
Reserved: 11.11.2025 Published: 11.02.2026 Updated: 11.02.2026

A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3. A user with Live Caller ID app extensions turned off could have identifying information leaked to the extensions.

Product Status

Vendor Apple
Product iOS and iPadOS
Versions
  • affected from unspecified to 26.3 (excl.)

References

Problem Types

  • A user with Live Caller ID app extensions turned off could have identifying information leaked to the extensions