CVE-2026-20658: Apple macOS
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
A package validation issue was addressed by blocking the vulnerable package. This issue is fixed in macOS Tahoe 26.3. An app may be able to gain root privileges.
Affected products
- Apple macOS: from 26.0, before 26.3 (fixed in 26.3)
Published 2026-02-11. Last modified 2026-06-17.