Description
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. Turning off "Load remote content in messages” may not apply to all mail previews.
Published: 2026-02-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential for unintended remote content loading
Action: Update Systems
AI Analysis

Impact

A logic issue in the mail preview functionality allowed remote content to load even when users disabled "Load remote content" in messages. This flaw could lead to unintended display of external images or scripts, potentially exposing user information or enabling phishing attempts. The issue is mitigated by additional checks introduced in the latest OS releases, which enforce the remote content restriction consistently.

Affected Systems

Apple iOS 18.7.5, iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, and macOS Tahoe 26.3 are secure against this flaw. Earlier versions lacking the update are affected and may still exhibit the logic problem.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk. EPSS below 1% suggests low likelihood of exploitation at this time, and the vulnerability is not cataloged in the CISA KEV list. A likely attack would involve a malicious email posting remote content that bypasses the user's setting, potentially compromising confidentiality or delivering phishing payloads. This inference is based on the described behavior of the flaw.

Generated by OpenCVE AI on April 15, 2026 at 20:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to iOS 18.7.5, iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, or macOS Tahoe 26.3 and later to receive the fix.
  • If an immediate update is not possible, disable remote content for all mail previews by turning off the "Load remote content" setting in Mail preferences.
  • Continue to monitor mail previews for unexpected remote content; report any persistent issues to Apple through the support pages linked in the advisory.

Generated by OpenCVE AI on April 15, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Title Remote Content Loading Logic Issue in iOS/iPadOS/macOS Mail Preview
Weaknesses CWE-710
CWE-754

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3, macOS Sonoma 14.8.4. Turning off "Load remote content in messages” may not apply to all mail previews. A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3. Turning off "Load remote content in messages” may not apply to all mail previews.

Fri, 13 Feb 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Thu, 12 Feb 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Vendors & Products Apple
Apple ios And Ipados
Apple macos

Wed, 11 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3, macOS Sonoma 14.8.4. Turning off "Load remote content in messages” may not apply to all mail previews.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-02T18:23:43.565Z

Reserved: 2025-11-11T14:43:07.867Z

Link: CVE-2026-20673

cve-icon Vulnrichment

Updated: 2026-02-13T17:49:22.108Z

cve-icon NVD

Status : Modified

Published: 2026-02-11T23:16:09.423

Modified: 2026-04-02T19:21:20.930

Link: CVE-2026-20673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T21:00:09Z