Injection Vulnerability in macOS Products by Apple
CVE-2026-20624

5.5MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
11 February 2026

What is CVE-2026-20624?

An injection vulnerability has been identified in certain macOS versions, allowing an attacker to potentially exploit the flaw and access sensitive user data. This issue was mitigated through improved validation measures in the subsequent software updates. Observing best practices and updating to the latest software versions is crucial for maintaining system security and protecting user information.

Affected Version(s)

macOS 0 < 14.8.4

macOS 0 < 15.7.4

macOS 0 < 26.3

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.