CVE-2026-20652
HIGH WAF: Medium
CVSS 7.5
Published: 2026-02-11
CWE-400 CWE-400
The issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.3, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3, Safari 26.3. A remote attacker may be able to cause a denial-of-service.
WAF Coverage Analysis
Uncontrolled Resource Consumption
Medium WAF Coverage
OWASP: A05:2021 Security Misconfiguration
912xxx - DOS Protection
Uncontrolled Resource Consumption
Medium WAF Coverage
OWASP: A05:2021 Security Misconfiguration
912xxx - DOS Protection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| apple | safari | up to 26.3 |
| apple | ipados | up to 18.7.5 |
| apple | ipados | 26.0 - 26.3 |
| apple | iphone_os | up to 18.7.5 |
| apple | iphone_os | 26.0 - 26.3 |
| apple | macos | up to 26.3 |
| apple | visionos | up to 26.3 |
References
- support.apple.com (Release Notes, Vendor Advisory)
- support.apple.com (Release Notes, Vendor Advisory)
- support.apple.com (Release Notes, Vendor Advisory)
- support.apple.com (Release Notes, Vendor Advisory)
- support.apple.com (Release Notes, Vendor Advisory)