CVE-2026-20650: Apple iPadOS
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A denial-of-service issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Bluetooth packets.
Affected products
- Apple iPadOS: before 26.3 (fixed in 26.3)
- Apple iPhone OS: before 26.3 (fixed in 26.3)
- Apple macOS: before 26.3 (fixed in 26.3)
- Apple tvOS: before 26.3 (fixed in 26.3)
- Apple visionOS: before 26.3 (fixed in 26.3)
- Apple watchOS: before 26.3 (fixed in 26.3)
Published 2026-02-11. Last modified 2026-06-17.