• News/
  • https://www.theregister.com/2026/02/12/apple_ios_263/

Apple patches decade-old iOS zero-day exploited in the wild

The Register
·
Connor Jones
·
Published Feb 12, 2026
·
Updated

Apple patched a zero-day vulnerability affecting every iOS version since 1.0, used in what the company calls an "extremely sophisticated attack" against targeted individuals. CVE-2026-20700, discovered by Google's Threat Analysis Group, affects dyld - Apple's dynamic linker - and allows attackers with memory write capability to execute arbitrary code. Apple said the flaw was exploited in the wild and may have been part of an exploit chain. Its advisory stated: "An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26." Google's researchers also referenced two December vulnerabilities in their report that both carry 8.8 CVSS scores. CVE-2025-14174 is an out-of-bounds memory access flaw in Google Chrome's ANGLE graphics engine on Mac that could be exploited through a malicious webpage. The other, CVE-2025-43529, is a use-after-free leading to code execution. Brian Milbier, deputy CISO at Huntress, said: "Think of dyld as the doorman for your phone. Every single app that wants to run must first pass through this doorman to be assembled and given permission to start. "Usually, the doorman checks credentials and places apps in a high-security 'sandbox' where they can't touch your private data. This vulnerability allows an attacker to trick the doorman into handing over a master key befo...

Read full article

Affected Software

1 affected component
Apple iOS<26
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a decade-old zero-day vulnerability in iOS that has been patched by Apple.

2

What security implications are discussed?

The article highlights an extremely sophisticated attack targeting specific individuals using the vulnerability.

3

What specific vulnerability is addressed in the article?

The vulnerability is identified as CVE-2026-20700, which affects all iOS versions since 1.0.

4

Which versions of iOS are affected by this vulnerability?

The vulnerability affects every version of iOS released up to version 26.

5

Who discovered the iOS zero-day vulnerability?

The vulnerability was discovered by Google's Threat Analysis Group.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203