CVE-2026-20676
MEDIUM WAF: Medium
CVSS 5.3
Published: 2026-02-11
CWE-400
This issue was addressed through improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, Safari 26.3, macOS Tahoe 26.3, visionOS 26.3. A website may be able to track users through Safari web extensions.
WAF Coverage Analysis
Uncontrolled Resource Consumption
Medium WAF Coverage
OWASP: A05:2021 Security Misconfiguration
912xxx - DOS Protection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| apple | safari | up to 26.3 |
| apple | ipados | up to 26.3 |
| apple | iphone_os | up to 26.3 |
| apple | macos | up to 26.3 |
| apple | visionos | up to 26.3 |
References
- support.apple.com (Release Notes, Vendor Advisory)
- support.apple.com (Release Notes, Vendor Advisory)
- support.apple.com (Release Notes, Vendor Advisory)
- support.apple.com (Release Notes, Vendor Advisory)