CVE-2026-20657 PUBLISHED

Assigner: apple
Reserved: 11.11.2025 Published: 25.03.2026 Updated: 25.03.2026

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5. Parsing a maliciously crafted file may lead to an unexpected app termination.

Product Status

Vendor Apple
Product iOS and iPadOS
Versions
  • affected from 0 to 18.7.7 (excl.)
Vendor Apple
Product macOS
Versions
  • affected from 0 to 14.8.5 (excl.)
  • affected from 0 to 15.7.5 (excl.)

References

Problem Types

  • Parsing a maliciously crafted file may lead to an unexpected app termination