Description
A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.
Published: 2026-02-11
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Sandbox escape via symbolic link race condition
Action: Immediate Patch
AI Analysis

Impact

Apple iOS, iPadOS, macOS, and visionOS have a race condition in symbolic link handling that can be exploited through a crafted shortcut. The flaw allows the shortcut to bypass sandbox restrictions, enabling an attacker to access data or resources normally confined to the sandbox. The vulnerability aligns with concurrency weaknesses (CWE-362, CWE-367) and can compromise confidentiality, integrity, and availability by elevating access privileges for the affected process.

Affected Systems

The affected products include Apple iOS and iPadOS, Apple macOS, and Apple visionOS. Versions impacted are iOS 18.7.5 and iOS 26.3, iPadOS 18.7.5 and iPadOS 26.3, macOS Sonoma 14.8.4 and macOS Tahoe 26.3, and visionOS 26.3. The vulnerabilities are fixed in the respective major releases listed above.

Risk and Exploitability

With a CVSS score of 9, this flaw is considered critical. The EPSS score is less than 1 %, indicating a low probability of exploitation at present. The flaw is not listed in the CISA KEV catalog. Because the attack vector is inferred to be local or user‑initiated through a shortcut, the likelihood of successful exploitation remains low, but once an attacker gains the ability to trigger the race condition, the impact is severe.

Generated by OpenCVE AI on April 16, 2026 at 00:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest operating‑system updates (iOS 18.7.5 or newer, macOS Sonoma 14.8.4 or newer, visionOS 26.3 or newer) to receive the symbolic‑link race condition fix.
  • Monitor for suspicious shortcut files and limit shortcut execution from untrusted sources until a reliable method to prevent sandbox escape is available.
  • Restrict the execution of user‑created shortcuts that use symbolic links by disabling shortcut execution for untrusted sources.

Generated by OpenCVE AI on April 16, 2026 at 00:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 01:15:00 +0000

Type Values Removed Values Added
Title Race condition in symbolic link handling allows sandbox escape on Apple OS

Thu, 02 Apr 2026 20:30:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Tahoe 26.3, macOS Sonoma 14.8.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. A shortcut may be able to bypass sandbox restrictions. A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.

Tue, 17 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-367
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 12 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
Weaknesses CWE-362
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:visionos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os
Metrics cvssV3_1

{'score': 9.0, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Thu, 12 Feb 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple visionos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple visionos

Wed, 11 Feb 2026 23:15:00 +0000

Type Values Removed Values Added
Description A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Tahoe 26.3, macOS Sonoma 14.8.4, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3. A shortcut may be able to bypass sandbox restrictions.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Macos Visionos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-04-07T14:34:35.405Z

Reserved: 2025-11-11T14:43:07.872Z

Link: CVE-2026-20677

cve-icon Vulnrichment

Updated: 2026-02-17T15:30:50.300Z

cve-icon NVD

Status : Modified

Published: 2026-02-11T23:16:10.107

Modified: 2026-04-02T19:21:21.663

Link: CVE-2026-20677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T01:00:19Z

Weaknesses