CVE-2026-20682 PUBLISHED

Assigner: apple
Reserved: 11.11.2025 Published: 11.02.2026 Updated: 11.02.2026

A logic issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An attacker may be able to discover a user’s deleted notes.

Product Status

Vendor Apple
Product iOS and iPadOS
Versions
  • affected from unspecified to 26.3 (excl.)
Vendor Apple
Product iOS and iPadOS
Versions
  • affected from unspecified to 18.7 (excl.)

References

Problem Types

  • An attacker may be able to discover a user’s deleted notes