Directory Path Handling Vulnerability in macOS and visionOS by Apple
CVE-2026-20625
5.5MEDIUM
What is CVE-2026-20625?
A vulnerability exists due to improper parsing in the handling of directory paths within macOS and visionOS. This flaw can enable applications to circumvent intended restrictions, potentially leading to unauthorized access to sensitive user data. Apple has released updates in macOS Sequoia 15.7.4, macOS Tahoe 26.3, macOS Sonoma 14.8.4, and visionOS 26.3 to address this security concern, enhancing path validation to prevent exploitation.
Affected Version(s)
macOS 0 < 14.8.4
macOS 0 < 15.7.4
macOS 0 < 26.3