CVE-2026-20636: Use After Free
Accessibility. A privacy issue was addressed by removing sensitive data.
Other sources
Accessibility. An inconsistent user interface issue was addressed with improved state management.
— Apple
Admin Framework. A parsing issue in the handling of directory paths was addressed with improved path validation.
— Apple
AppleEvents. An authorization issue was addressed with improved state management.
— Apple
AppleKeyStore. A use after free issue was addressed with improved memory management.
— Apple
AppleMobileFileIntegrity. A parsing issue in the handling of directory paths was addressed with improved path validation.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.3 - Remove
Remove
vulnerable codefrom your environment.Remove the vulnerable code as part of the fix described in the material.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-20660
- CVE-2026-20656
- CVE-2026-20652
- CVE-2026-20608
- CVE-2026-20676
- CVE-2026-20644
- CVE-2026-20636
- CVE-2026-20635
- CVE-2026-20645
- CVE-2026-20674
- CVE-2026-20637
- CVE-2026-20650
- CVE-2026-20638
- CVE-2026-20686
- CVE-2026-20611
- CVE-2026-20609
- CVE-2026-20617
- CVE-2026-20615
- CVE-2026-20627
- CVE-2025-14174
- CVE-2025-43529
- CVE-2026-20700
- CVE-2026-20668
- CVE-2026-20649
- CVE-2026-20675
- CVE-2026-20634
- CVE-2026-20654
- CVE-2026-20626
- CVE-2026-20671
- CVE-2026-20663
- CVE-2025-59375
- CVE-2026-20667
- CVE-2026-20655
- CVE-2026-20677
- CVE-2026-20694
- CVE-2026-20642
- CVE-2026-20628
- CVE-2026-20678
- CVE-2026-28855
- CVE-2026-20682
- CVE-2026-20653
- CVE-2026-20680
- CVE-2026-20641
- CVE-2026-20606
- CVE-2026-20640
- CVE-2026-20661
- CVE-2026-20621
- CVE-2026-20625
- CVE-2026-20616
- CVE-2026-20669
- CVE-2026-20670
- CVE-2026-20624
- CVE-2026-20639
- CVE-2026-20681
- CVE-2026-20629
- CVE-2026-20601
- CVE-2026-20623
- CVE-2026-20620
- CVE-2026-20630
- CVE-2026-20672
- CVE-2026-20673
- CVE-2026-20651
- CVE-2026-20603
- CVE-2026-20666
- CVE-2026-20614
- CVE-2026-20658
- CVE-2026-20610
- CVE-2026-20622
- CVE-2026-20648
- CVE-2026-20662
- CVE-2026-20647
- CVE-2026-20612
- CVE-2026-20699
- CVE-2026-20619
- CVE-2026-20618
- CVE-2026-20605
- CVE-2026-20646
- CVE-2026-20602
Frequently Asked Questions
What is the severity of CVE-2026-20636?
CVE-2026-20636 is classified as a moderate severity vulnerability affecting several Apple products.
How do I fix CVE-2026-20636?
To fix CVE-2026-20636, update your software to the latest version 26.3 or later for affected Apple products.
Which products are affected by CVE-2026-20636?
CVE-2026-20636 affects Apple visionOS, iOS, iPadOS, macOS Tahoe, and Safari versions up to 26.3.
What type of vulnerabilities are addressed in CVE-2026-20636?
CVE-2026-20636 addresses a privacy issue and improves state management in user interfaces and path validation.
What are the potential risks of not addressing CVE-2026-20636?
Not addressing CVE-2026-20636 may expose sensitive data and lead to inconsistent user interface behavior or path handling issues.