CVE-2026-20650

HIGH WAF: Medium
CVSS 7.5 Published: 2026-02-11
CWE-400 CWE-400

A denial-of-service issue was addressed with improved validation. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Bluetooth packets.

WAF Coverage Analysis

Uncontrolled Resource Consumption Medium WAF Coverage

OWASP: A05:2021 Security Misconfiguration

912xxx - DOS Protection
Uncontrolled Resource Consumption Medium WAF Coverage

OWASP: A05:2021 Security Misconfiguration

912xxx - DOS Protection

Affected Software

VendorProductVersion
appleipadosup to 26.3
appleiphone_osup to 26.3
applemacosup to 26.3
appletvosup to 26.3
applevisionosup to 26.3
applewatchosup to 26.3

References

Back to CVE Database