TROYANOSYVIRUS
Volver a CVEs

CVE-2026-20616

HIGH
8.8

Descripcion

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. Processing a maliciously crafted USD file may lead to unexpected app termination.

Detalles CVE

Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado2/11/2026
Ultima modificacion4/2/2026
Fuentenvd
Avistamientos honeypot0

Productos afectados

apple:ipadosapple:iphone_osapple:macosapple:visionos

Debilidades (CWE)

CWE-787

Referencias

https://support.apple.com/en-us/126347(product-security@apple.com)
https://support.apple.com/en-us/126348(product-security@apple.com)
https://support.apple.com/en-us/126350(product-security@apple.com)
https://support.apple.com/en-us/126353(product-security@apple.com)
https://www.zerodayinitiative.com/advisories/ZDI-26-176/(134c704f-9b21-4f2e-91b3-4a467353bcc0)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.