This is the locksmith's master key — it doesn't open the door by itself, but once you have any key blank, it cuts a perfect copy
CVE-2026-20700 is a memory corruption flaw in dyld, Apple's Dynamic Link Editor — the foundational component that loads every shared library on every process launch across iOS, iPadOS, macOS, tvOS, watchOS, and visionOS. The root cause is a TOCTOU race condition in dyld's state management that allows an attacker who already holds a memory-write primitive to recover a stale stack frame and abuse dyld's chained fixup mechanism as a PAC signing oracle. This converts an otherwise limited memory corruption into full arbitrary code execution that bypasses Pointer Authentication Codes (PAC) on arm64e devices. Affected versions include all Apple platforms before iOS/iPadOS 26.3, macOS Tahoe 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, tvOS 26.3, watchOS 26.3, and visionOS 26.3. Backported fixes also landed in iOS/iPadOS 18.7.5.
Apple rated this HIGH at 7.8 with a local attack vector, which accurately reflects that the bug *alone* requires prior memory-write capability. However, the vendor score understates operational risk because this CVE doesn't live alone — it was weaponized in the wild as a critical link in Google TAG's documented DarkSword spyware chain alongside two WebKit flaws (CVE-2025-14174 and CVE-2025-43529). In that chain, a single tap on a link delivers full device takeover: browser exploit → memory write → CVE-2026-20700 PAC bypass → persistent spyware installation. Apple themselves called it "an extremely sophisticated attack against specific targeted individuals." The CVSS local-vector framing hides the fact that this is a force multiplier — any future memory corruption on any Apple platform becomes dramatically more dangerous while this bug remains unpatched. CISA added it to KEV within 24 hours of disclosure. We assess this at 8.2 HIGH, reflecting the confirmed weaponization and strategic amplifier role.
5 steps from start to impact.
Deliver weaponized link to target
- Target must open the link in a WebKit-backed view
- Attacker must have a companion WebKit exploit (e.g., CVE-2025-14174 or CVE-2025-43529)
- Requires a separate, independent browser vulnerability — CVE-2026-20700 alone cannot achieve initial access
- Modern link-scanning by mobile threat defense (MTD) products or email gateways may flag known C2 domains
Achieve memory write via WebKit renderer
- Unpatched WebKit on the target device
- WebKit sandbox must not block the write target
- WebKit patches for the companion CVEs were released simultaneously, so a fully patched device blocks this step
- iOS WebKit process isolation and sandboxing limit what memory regions are writable
Trigger TOCTOU race in dyld state management
- Active memory write primitive from Step 2
- Ability to trigger a library load or dlopen call from the compromised process
- The race window is timing-sensitive; reliability varies by device model and load
- arm64e PAC context values must be correctly predicted for the target process
Use dyld as PAC signing oracle
dispatch_source_t timer handler. When the event loop fires, the pointer is called naturally through the dispatch mechanism — no direct invocation needed. This effectively turns dyld into a signing oracle: the attacker can sign arbitrary pointers with both IA and IB keys, completely bypassing PAC on arm64e devices.- Successful exploitation of the TOCTOU race in Step 3
- Process must have an active dispatch event loop (virtually all iOS/macOS processes do)
- The technique is complex and requires deep knowledge of dyld internals and PAC signing contexts
- bytehazard's PoC demonstrates feasibility but notes reliability challenges on newer A-series chips
Achieve arbitrary code execution and install payload
- Successful PAC bypass from Step 4
- Kernel or sandbox-escape primitive (may be additional undisclosed CVE or known technique)
- Full chain requires 3+ vulnerabilities working in concert — extremely expensive to develop
- Apple's Lockdown Mode, if enabled, blocks several persistence mechanisms
- Traditional endpoint antivirus — AV products do not inspect dyld internals or detect PAC oracle abuse. The exploitation occurs entirely within legitimate OS components using valid code paths.
- Network firewalls or IPS alone — The initial delivery is a URL over HTTPS; the payload delivery is encrypted. Without TLS inspection and URL reputation, network controls are blind to the initial access vector.
- App Store restrictions / sideloading blocks — The DarkSword chain does not require a malicious app. It exploits WebKit through Safari or in-app browsers, which are permitted on all managed devices.
- Disabling iCloud or Apple ID — The vulnerability is in dyld, a core OS component unrelated to cloud services. Disabling cloud features does not reduce the attack surface for this CVE.
The supporting signals.
| In-the-wild status | Confirmed active exploitation. Google TAG discovered this being used in the DarkSword spyware chain targeting journalists and political dissidents. Apple acknowledged exploitation in "extremely sophisticated" targeted attacks. CISA added to KEV on 2026-02-12, one day after disclosure. |
|---|---|
| Proof-of-concept | Public PoC available. bytehazard/CVE-2026-20700 demonstrates using dyld's chained fixup mechanism as a PAC signing oracle on arm64e iOS. A second repo by R3n3r0 also exists. CIRCL Vulnerability-Lookup aggregated 12 exploitation sightings and 1 published PoC. The PoC is a *primitive demonstrator*, not a full exploit chain. |
| EPSS | 1.32% probability of exploitation in next 30 days (69th percentile). Notably low for a KEV-listed CVE — reflects the targeted nature and high chain complexity rather than mass exploitation potential. |
| KEV status | Listed 2026-02-12. Added the day after Apple's patch release. Federal agencies were required to remediate by the BOD 22-01 deadline. |
| CVSS vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H — 7.8 HIGH. The AV:L (Local) and PR:L (Low privilege) are technically accurate for this CVE in isolation, but obscure its role as a chained primitive where initial access is remote via WebKit. |
| Affected versions | All Apple platforms before: iOS/iPadOS 26.3, macOS Tahoe 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, iOS/iPadOS 18.7.5, tvOS 26.3, watchOS 26.3, visionOS 26.3. macOS Ventura (13.x) and earlier are EOL with no patch. |
| Fixed versions | iOS/iPadOS 26.3, macOS Tahoe 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, iOS 18.7.5, tvOS 26.3, watchOS 26.3, visionOS 26.3, Safari 26.3. Released 2026-02-11. |
| Exploit chain companions | Part of the DarkSword chain with CVE-2025-14174 and CVE-2025-43529 (both WebKit). All three were patched in the same release. The chain achieves full device compromise from a single link click. |
| Scanning / exposure | Not remotely scannable. This is a local privilege-escalation / PAC-bypass primitive — there is no network service to fingerprint. GreyNoise and Shodan have no relevant tags. Exposure assessment is purely a function of fleet OS version inventory via MDM or endpoint agents. |
| Discoverer | Google Threat Analysis Group (TAG) — reported to Apple, which patched within the same coordinated disclosure. TAG tracks nation-state and commercial surveillance vendor activity. Additional analysis by iVerify, Lookout, and NashTech Global (DarkSword PAC bypass writeup). |
Sources.
- Apple Security Release - iOS 26.3 / iPadOS 26.3
- CISA KEV Addition Alert (2026-02-12)
- The Hacker News - Apple Fixes Exploited Zero-Day
- NashTech - DarkSword PAC Bypass Analysis (Part 3)
- SecurityOnline - Apple Zero-Day CVE-2026-20700 Exploited in the Wild
- Penligent - CVE-2026-20700 The dyld Zero Day Reality Check
- SOC Prime - CVE-2026-20700 Analysis
- GitHub Advisory - GHSA-j5x8-2r52-c3ff
Why this verdict
- Confirmed weaponization overrides CVSS isolation framing. The CVSS 7.8 scores this bug in a vacuum with
AV:L. In reality, it was chained with WebKit flaws to achieve one-click remote device takeover in the DarkSword spyware campaign. The base score does not account for the *amplifier* nature of a PAC bypass primitive. - KEV listing with active exploitation removes theoretical friction. The chain complexity (3+ CVEs) would normally suggest low real-world probability. But Google TAG confirmed it was already deployed against real targets — the friction was overcome by a well-resourced adversary, and the PoC is now public, lowering the barrier for second-movers.
- Role multiplier: universal OS component with high-value role exposure. dyld runs on every Apple device. In enterprise contexts, affected populations include (a) *corporate iPhones/iPads* enrolled in MDM with SSO tokens, VPN credentials, and access to email/Slack/Teams — compromise leaks corporate identity; (b) *macOS developer workstations* holding code-signing certificates, SSH keys, and CI/CD pipeline access — compromise enables supply-chain attacks; (c) *executive mobile devices* — the documented attack target. The blast radius on any high-value device is full device takeover → credential theft → lateral movement into corporate infrastructure. ≥30% of enterprise Apple devices fall into categories (a) or (b), well above the 1% floor threshold.
- PAC bypass is a strategic primitive. Even after the companion WebKit CVEs are patched, CVE-2026-20700 remains independently valuable to any attacker who obtains *any* memory-write primitive on an unpatched Apple device. It converts partial compromise into complete PAC defeat — this is a capability accelerator, not just a single bug.
- EPSS undercounts due to targeting profile. The 1.32% EPSS reflects mass-exploitation probability, which is low for a targeted spyware tool. But enterprise risk assessment must weight the *consequence* of exploitation, not just the probability. For organizations in the target profile (media, government, NGOs, defense contractors), the effective risk is orders of magnitude higher than EPSS suggests.
Why not higher?
We do not elevate to CRITICAL because the vulnerability cannot be exploited standalone — it requires a separate memory-write primitive, meaning a companion vulnerability must also be unpatched. The documented chain requires three CVEs working in concert, which limits the attacker population to well-resourced groups. Additionally, Apple patched all three chain components simultaneously, so a single update cycle closes the entire attack path. The local attack vector and low-privilege requirement are real constraints that keep this below the CRITICAL threshold.
Why not lower?
Downgrading below HIGH is blocked by the deployment-role floor rule: dyld is a canonical OS-infrastructure component present on every Apple device, and ≥30% of enterprise Apple endpoints occupy high-value roles (MDM-enrolled corporate devices, developer workstations). Full device takeover on these endpoints produces credential theft, supply-chain pivot, or espionage outcomes. The KEV listing with confirmed nation-state exploitation further prevents any downgrade — this is not theoretical risk. The public PoC demonstrating the PAC signing oracle lowers the reproduction barrier for second-tier threat actors.
Crowdsourced verification payload.
Run this script on each macOS target host (no root required). Usage: bash check_cve_2026_20700.sh. For iOS/iPadOS fleet assessment, query your MDM (Jamf, Intune, Kandji) for device OS versions below the patched thresholds listed in the script comments.
#!/bin/bash
# CVE-2026-20700 Verification Script
# Checks macOS version against patched releases for dyld memory corruption fix
# Exit codes: 0 = PATCHED, 1 = VULNERABLE, 2 = UNKNOWN
set -euo pipefail
OS_VERSION=$(sw_vers -productVersion 2>/dev/null || true)
if [ -z "$OS_VERSION" ]; then
echo "UNKNOWN - Cannot determine macOS version. Is this a macOS host?"
exit 2
fi
MAJOR=$(echo "$OS_VERSION" | cut -d. -f1)
MINOR=$(echo "$OS_VERSION" | cut -d. -f2)
PATCH=$(echo "$OS_VERSION" | cut -d. -f3)
PATCH=${PATCH:-0}
echo "[*] CVE-2026-20700 check on macOS $OS_VERSION"
echo "[*] Patched versions: Tahoe >=26.3, Sequoia >=15.7.4, Sonoma >=14.8.4"
echo "[*] EOL (no fix): Ventura 13.x and earlier"
echo ""
version_gte() {
local a1=$1 a2=$2 a3=$3 b1=$4 b2=$5 b3=$6
if [ "$a1" -gt "$b1" ] 2>/dev/null; then return 0; fi
if [ "$a1" -lt "$b1" ] 2>/dev/null; then return 1; fi
if [ "$a2" -gt "$b2" ] 2>/dev/null; then return 0; fi
if [ "$a2" -lt "$b2" ] 2>/dev/null; then return 1; fi
if [ "$a3" -ge "$b3" ] 2>/dev/null; then return 0; fi
return 1
}
if [ "$MAJOR" -ge 27 ]; then
echo "PATCHED - macOS $OS_VERSION is newer than all affected releases."
exit 0
elif [ "$MAJOR" -eq 26 ]; then
if version_gte "$MAJOR" "$MINOR" "$PATCH" 26 3 0; then
echo "PATCHED - macOS Tahoe $OS_VERSION includes the fix."
exit 0
else
echo "VULNERABLE - macOS Tahoe $OS_VERSION is below 26.3. Update immediately."
exit 1
fi
elif [ "$MAJOR" -eq 15 ]; then
if version_gte "$MAJOR" "$MINOR" "$PATCH" 15 7 4; then
echo "PATCHED - macOS Sequoia $OS_VERSION includes the backported fix."
exit 0
else
echo "VULNERABLE - macOS Sequoia $OS_VERSION is below 15.7.4. Update immediately."
exit 1
fi
elif [ "$MAJOR" -eq 14 ]; then
if version_gte "$MAJOR" "$MINOR" "$PATCH" 14 8 4; then
echo "PATCHED - macOS Sonoma $OS_VERSION includes the backported fix."
exit 0
else
echo "VULNERABLE - macOS Sonoma $OS_VERSION is below 14.8.4. Update immediately."
exit 1
fi
else
echo "VULNERABLE - macOS $OS_VERSION ($MAJOR.x) is end-of-life. No patch available for CVE-2026-20700."
echo " Upgrade to a supported macOS release immediately."
exit 1
fi