Directory Path Handling Vulnerability in macOS and visionOS by Apple
CVE-2026-20625
5.5MEDIUM
What is CVE-2026-20625?
A vulnerability exists due to improper parsing in the handling of directory paths within macOS and visionOS. This flaw can enable applications to circumvent intended restrictions, potentially leading to unauthorized access to sensitive user data. Apple has released updates in macOS Sequoia 15.7.4, macOS Tahoe 26.3, macOS Sonoma 14.8.4, and visionOS 26.3 to address this security concern, enhancing path validation to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
macOS < 26.3
macOS < 15.7
macOS < 14.8
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved