CVE-2026-20696

medium
Published 2026-05-11 ยท Modified 2026-05-12
CVSS v3
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.5

Description

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

Predictions

Exploit likelihood
55%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Apple Security HT ยท View original โ†— ยท proprietary-no-redistribution
Full prose not cached โ€” VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Affected

VendorProductVersion
apple802.1XmacOS Tahoe
appleAccountsmacOS Tahoe
appleAdmin FrameworkmacOS Tahoe
appleAppleMobileFileIntegritymacOS Tahoe
appleAppleScriptmacOS Tahoe
appleArchive UtilitymacOS Tahoe
appleArchive UtilitymacOS Tahoe
appleAudiomacOS Tahoe
appleAudiomacOS Tahoe
appleCalling FrameworkmacOS Tahoe
appleClipboardmacOS Tahoe
appleCoreMediamacOS Tahoe
appleCoreServicesmacOS Tahoe
appleCoreServicesmacOS Tahoe
appleCoreUtilsmacOS Tahoe
appleCrash ReportermacOS Tahoe
appleCUPSmacOS Tahoe
appleCUPSmacOS Tahoe
applecurlmacOS Tahoe
appleDeviceLinkmacOS Tahoe
appleDiagnosticsmacOS Tahoe
appleFile SystemmacOS Tahoe
appleGeoServicesmacOS Tahoe
appleGPU DriversmacOS Tahoe
appleiCloudmacOS Tahoe
appleiCloudmacOS Tahoe
appleImageIOmacOS Tahoe
appleIOGraphicsmacOS Tahoe
appleIOGraphicsmacOS Tahoe
appleKernelmacOS Tahoe

OS impact

OSVersionStatusFixed in
macos macosaffected26.4

References

CWEs

CWE-862

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.