Symlink Handling Vulnerability in Apple macOS Products
CVE-2026-20633

5.5MEDIUM

Key Information:

Vendor

Apple

Status
Vendor
CVE Published:
25 March 2026

What is CVE-2026-20633?

This vulnerability involves an improper handling of symlinks in Apple's macOS products, potentially allowing applications to access user-sensitive data without appropriate permissions. The issue has been addressed in updates for macOS Sequoia, Sonoma, and Tahoe, improving the overall security posture of affected systems. Users are urged to update their macOS versions to protect against unauthorized data access.

Affected Version(s)

macOS 0 < 14.8.5

macOS 0 < 15.7.5

macOS 0 < 26.4

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.