CVE-2026-20655

MEDIUM WAF: Low
CVSS 5.5 Published: 2026-02-11
CWE-287

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, iOS 18.7.5 and iPadOS 18.7.5. An attacker with physical access to a locked device may be able to view sensitive user information.

WAF Coverage Analysis

Improper Authentication Low WAF Coverage

OWASP: A07:2021 Identification and Authentication Failures

Affected Software

VendorProductVersion
appleipadosup to 18.7.5
appleipados26.0 - 26.3
appleiphone_osup to 18.7.5
appleiphone_os26.0 - 26.3

References

Back to CVE Database