{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-20700",
  "revision": 1,
  "title": "Apple platforms — memory corruption completes an exploit chain",
  "summary": "A state-management flaw across Apple's operating systems lets an attacker who can already write memory run code of their choosing. Apple says it was used in an extremely sophisticated attack on specific individuals running iOS before 26.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.8,
    "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.01343,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-02-12",
    "prerequisites": "The attacker must already be able to write memory on the device — this is the later stage of a chain."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "iOS 26.3",
      "iPadOS 26.3",
      "macOS Tahoe 26.3",
      "tvOS 26.3",
      "visionOS 26.3",
      "watchOS 26.3"
    ]
  },
  "mitre_attack": [
    "T1068"
  ],
  "kill_chain": "privilege_escalation",
  "recommended_action": "Update to iOS and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3 or watchOS 26.3 now; give the devices of likely targets a closer look.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-20700",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-20700",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-20700",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-20700",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/126346"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/126348"
    },
    {
      "type": "vendor_advisory",
      "url": "https://support.apple.com/en-us/126351"
    }
  ],
  "published_at": "2026-02-11T23:16:10.670Z",
  "issued_at": "2026-09-24T08:51:39.744Z",
  "tags": [
    "apple",
    "ios",
    "macos",
    "memory-corruption",
    "targeted-attack",
    "kev"
  ]
}
