Apple Issues Patches for Actively Exploited Zero-Day Impacting iOS, macOS and Other Platforms
Apple rolled out software updates on Wednesday for iOS, iPadOS, macOS Tahoe, tvOS, watchOS and visionOS to remediate a zero-day vulnerability that the company says has been abused in targeted, highly sophisticated attacks.
The flaw, cataloged as CVE-2026-20700 (CVSS: N/A), is a memory corruption bug found in dyld, Apple’s Dynamic Link Editor. If an attacker already has the ability to write to memory on an affected device, exploiting this weakness could enable them to run arbitrary code. Google’s Threat Analysis Group (TAG) is credited with discovering and reporting the issue.
In its advisory, Apple acknowledged reports that the vulnerability may have been used in an “extremely sophisticated” operation aimed at particular individuals running versions of iOS prior to iOS 26. The company also noted that two other fixes – CVE-2025-14174 and CVE-2025-43529 – were issued in connection with that report.
Those two December 2025 fixes addressed related problems: CVE-2025-14174 (CVSS: 8.8) involved an out-of-bounds memory access in the ANGLE Metal renderer, and CVE-2025-43529 (CVSS: 8.8) was a use-after-free flaw in WebKit that could be weaponized to execute code when a browser processed malicious content. Google initially disclosed that CVE-2025-14174 had been exploited in the wild.
Updates available now:
– iOS 26.3 and iPadOS 26.3 – iPhone 11 and newer; iPad Pro 12.9-inch (3rd gen and later); iPad Pro 11-inch (1st gen and later); iPad Air (3rd gen and later); iPad (8th gen and later); iPad mini (5th gen and later).
– macOS Tahoe 26.3 – Macs running macOS Tahoe.
– tvOS 26.3 – Apple TV HD and Apple TV 4K (all models).
– watchOS 26.3 – Apple Watch Series 6 and later.
– visionOS 26.3 – Apple Vision Pro (all models).
Apple additionally issued security updates for older releases of iOS, iPadOS, macOS and Safari to fix a variety of other vulnerabilities. With this rollout, the company has addressed its first actively exploited zero-day of 2026; in the previous year Apple patched nine zero-days that were seen used in the wild.