Apple patched a zero-day vulnerability affecting every iOS version since 1.0, used in what the company calls an "extremely sophisticated attack" against targeted individuals. CVE-2026-20700, discovered by Google's Threat Analysis Group, affects dyld - Apple's dynamic linker - and allows attackers with memory write capability to execute arbitrary code. Apple said the flaw was exploited in the wild and may have been part of an exploit chain. Its advisory stated: "An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26." Google's researchers also referenced two December vulnerabilities in their report that both carry 8.8 CVSS scores. CVE-2025-14174 is an out-of-bounds memory access flaw in Google Chrome's ANGLE graphics engine on Mac that could be exploited through a malicious webpage. The other, CVE-2025-43529, is a use-after-free leading to code execution. Brian Milbier, deputy CISO at Huntress, said: "Think of dyld as the doorman for your phone. Every single app that wants to run must first pass through this doorman to be assembled and given permission to start. "Usually, the doorman checks credentials and places apps in a high-security 'sandbox' where they can't touch your private data. This vulnerability allows an attacker to trick the doorman into handing over a master key befo...
Apple patches decade-old iOS zero-day exploited in the wild
The Register
·Connor Jones
·Published Feb 12, 2026
·Updated
Affected Software
1 affected component
Apple iOS<26
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a decade-old zero-day vulnerability in iOS that has been patched by Apple.
2
What security implications are discussed?
The article highlights an extremely sophisticated attack targeting specific individuals using the vulnerability.
3
What specific vulnerability is addressed in the article?
The vulnerability is identified as CVE-2026-20700, which affects all iOS versions since 1.0.
4
Which versions of iOS are affected by this vulnerability?
The vulnerability affects every version of iOS released up to version 26.
5
Who discovered the iOS zero-day vulnerability?
The vulnerability was discovered by Google's Threat Analysis Group.