CVE-2026-20649: Apple iPadOS

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A logging issue was addressed with improved data redaction. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3. A user may be able to view sensitive user information.

Affected products

  • Apple iPadOS: before 26.3 (fixed in 26.3)
  • Apple iPhone OS: before 26.3 (fixed in 26.3)
  • Apple macOS: before 26.3 (fixed in 26.3)
  • Apple tvOS: before 26.3 (fixed in 26.3)
  • Apple watchOS: before 26.3 (fixed in 26.3)

Published 2026-02-11. Last modified 2026-06-17.