Apple Zero-Day CVE-2026-20700: Memory Corruption Enabling Arbitrary Code Execution — Google TAG-Discovered 'Extremely Sophisticated' Targeted Attack
Apple Zero-Day CVE-2026-20700 (TL-2026-0075) is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-02-12. It has no confirmed attribution, references 3 CVEs (CVE-2026-20700, CVE-2025-14174, CVE-2025-43529), maps to 26 MITRE ATT&CK techniques (T1005, T1014, T1037), and is covered by 9 detection rules and 30 indicators of compromise.
Key facts for TL-2026-0075
- Threat ID
- TL-2026-0075
- Severity
- CRITICAL
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-02-12
- Last reviewed
- 2026-02-12
- Attribution confidence
- NONE
- Motivation
- ESPIONAGE
- Target sectors
- Government, Civil Society, Media, Human Rights, Political Opposition, Legal
- Target regions
- Global — targeted individuals
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in Apple Zero-Day CVE-2026-20700
Malware and tooling: MVT (Mobile Verification Toolkit) detection indicators — known Pegasus/Predator/spyware artifacts in sysdiagnose logs
Apple's February 11, 2026 security updates patch CVE-2026-20700, an actively exploited zero-day memory corruption vulnerability affecting ALL Apple platforms — iOS/iPadOS 26.3, macOS Tahoe 26.3, watchOS 26.3, tvOS 26.3, and visionOS 26.3. Discovered by Google's Threat Analysis Group (TAG), Apple confirms the vulnerability was exploited in 'an extremely sophisticated attack against specific targeted individuals' running iOS versions before iOS 26, as part of a three-CVE infection chain with CVE-2025-14174 and CVE-2025-43529 (both patched in December 2025). The vulnerability enables an attacker with memory write capability to achieve arbitrary code execution — the hallmark of commercial spyware operations. Google TAG discovery attribution strongly suggests a commercial surveillance vendor (CSV) exploit chain, consistent with NSO Group Pegasus, Intellexa Predator, or similar mercenary spyware. The vulnerability class (memory corruption addressed with improved state management) indicates a use-after-free or type confusion primitive enabling kernel or process-level code execution.
How Apple Zero-Day CVE-2026-20700 works
CVE-2026-20700 is a critical Apple zero-day vulnerability — a memory corruption issue addressed with improved state management — that grants attackers with memory write capability the ability to execute arbitrary code on affected devices. The vulnerability was discovered by Google's Threat Analysis Group (TAG), the team specifically tasked with tracking government-backed hacking and commercial surveillance vendors. Apple's advisory explicitly states awareness of exploitation 'in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26,' a phrasing Apple reserves exclusively for nation-state or commercial spyware operations.
THREE-CVE INFECTION CHAIN: The exploitation chain combines three vulnerabilities in sequence: 1. CVE-2025-14174 — First stage (details undisclosed, patched December 2025) 2. CVE-2025-43529 — Second stage (details undisclosed, patched December 2025) 3. CVE-2026-20700 — Final stage: memory corruption → arbitrary code execution (patched February 11, 2026)
The first two chain CVEs were patched in Apple's December 2025 update, but CVE-2026-20700 remained unpatched until February 2026 — creating a multi-month window where users who applied December updates were still partially vulnerable through the third chain component. Users who did NOT update to December 2025 were vulnerable to the complete three-CVE chain.
AFFECTED PLATFORMS (ALL Apple ecosystem): - iOS 26.3 and iPadOS 26.3 — iPhone 11+, iPad Pro 3rd gen+, iPad Air 3rd gen+, iPad 8th gen+, iPad mini 5th gen+ - iOS 18.7.5 and iPadOS 18.7.5 — iPhone XS/XR, iPad 7th gen (backported fixes, though CVE-2026-20700 specific patch is in 26.3) - macOS Tahoe 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4 - watchOS 26.3 — Apple Watch Series 6+ - tvOS 26.3 — Apple TV HD and 4K (all models) - visionOS 26.3 — Apple Vision Pro (all models) - Safari 26.3 — macOS Sonoma and Sequoia
GOOGLE TAG ATTRIBUTION SIGNIFICANCE: Google TAG discovers and reports vulnerabilities used by commercial surveillance vendors (CSVs) and government-backed threat actors. TAG's involvement in CVE-2026-20700 strongly indicates the exploit was deployed by a commercial spyware operation — consistent with vendors like NSO Group (Pegasus), Intellexa (Predator), Variston, Candiru, or similar mercenary spyware providers. Apple's 'extremely sophisticated attack against specific targeted individuals' language is the canonical indicator for targeted surveillance operations against journalists, activists, dissidents, opposition politicians, and human rights defenders.
ADDITIONAL HIGH-SEVERITY CVEs IN FEBRUARY 2026 APPLE UPDATE: - CVE-2026-20617 — Root privilege escalation via race condition (multiple platforms) - CVE-2026-20615 — Root privilege escalation via path handling (multiple platforms) - CVE-2026-20626 — Malicious app root privilege escalation - CVE-2026-20660 — Remote arbitrary file write via path handling - CVE-2026-20667 — Sandbox escape via logic issue - CVE-2026-20628 — Sandbox escape via permissions issue - CVE-2026-20611 — Media file processing memory corruption (Trend Micro ZDI) - CVE-2026-20671 — Network traffic interception via logic issue
This update represents Apple's response to an active commercial spyware campaign, with Google TAG providing the initial discovery.
MITRE ATT&CK techniques used in TL-2026-0075
collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1123 Audio Capture; T1125 Video Capture
defense-evasion
T1014 Rootkit; T1070 Indicator Removal; T1211 Exploitation for Stealth
persistence
T1037 Boot or Logon Initialization Scripts; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
exfiltration
T1041 Exfiltration Over C2 Channel
privilege-escalation
T1068 Exploitation for Privilege Escalation
command-and-control
T1071 Application Layer Protocol; T1573 Encrypted Channel
discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
initial-access
T1190 Exploit Public-Facing Application; T1566 Phishing
execution
T1203 Exploitation for Client Execution; T1204 User Execution
Collection
defense-impairment
credential-access
T1555 Credentials from Password Stores
resource-development
Remediation for Apple Zero-Day CVE-2026-20700
Patches
- iOS 26.3 / iPadOS 26.3 (February 11, 2026) — CVE-2026-20700 + 20+ additional CVEs
- iOS 18.7.5 / iPadOS 18.7.5 (February 11, 2026) — Legacy device support
- macOS Tahoe 26.3 (February 11, 2026) — CVE-2026-20700 + 30+ additional CVEs
- macOS Sequoia 15.7.4 (February 11, 2026)
- macOS Sonoma 14.8.4 (February 11, 2026)
- watchOS 26.3 (February 11, 2026) — CVE-2026-20700
- tvOS 26.3 (February 11, 2026) — CVE-2026-20700
- visionOS 26.3 (February 11, 2026) — CVE-2026-20700
- Safari 26.3 (February 11, 2026)
Immediate actions
- UPDATE ALL APPLE DEVICES IMMEDIATELY — iOS 26.3, macOS Tahoe 26.3, watchOS 26.3, tvOS 26.3, visionOS 26.3
- For older iPhones (XS/XR): update to iOS 18.7.5
- For older macOS: update to macOS Sequoia 15.7.4 or macOS Sonoma 14.8.4
- High-risk individuals (journalists, activists, dissidents): enable Apple Lockdown Mode immediately
- Verify December 2025 update was applied (patches CVE-2025-14174 and CVE-2025-43529 — first two chain components)
Workarounds
- Enable Lockdown Mode (Settings > Privacy & Security > Lockdown Mode) — significantly reduces attack surface for spyware chains
- Restart devices regularly — disrupts non-persistent implants (most modern iOS spyware is non-persistent due to Pointer Authentication)
- Do not open unsolicited links or attachments — common spyware delivery vector
- For Apple Mail users: be aware that HTML-formatted emails containing malicious web content create additional risk
- Monitor for Apple threat notification alerts — Apple directly notifies targets of state-sponsored attacks
Longer-term hardening
- Enable automatic updates on ALL Apple devices to minimize zero-day exposure windows
- Deploy mobile device management (MDM) to enforce timely OS updates across organizational fleets
- High-value targets should use Apple Lockdown Mode as a permanent security posture
- Monitor Apple threat notifications — Apple sends direct alerts to targets of state-sponsored attacks
- Consider Google Advanced Protection Program for Gmail/Google accounts of at-risk individuals
- Implement endpoint detection on managed Apple devices to identify anomalous post-exploitation behavior
CVEs associated with Apple Zero-Day CVE-2026-20700
Weaknesses (CWE) in Apple Zero-Day CVE-2026-20700
CWE-787, CWE-119, CWE-416
Timeline of Apple Zero-Day CVE-2026-20700
- Google TAG discovers exploitation of CVE-2026-20700 as part of three-CVE chain (CVE-2025-14174 + CVE-2025-43529 + CVE-2026-20700) targeting specific individuals running iOS versions before iOS 26. Apple describes it as 'extremely sophisticated.' Source: Apple/Google TAG
- Apple December 2025 security update patches CVE-2025-14174 and CVE-2025-43529 — the first two components of the three-CVE infection chain. Users who applied this update were protected against the full chain. Source: Apple Security
- February 2026 Apple updates also fix 20+ additional CVEs including 3 root privilege escalation bugs (CVE-2026-20617, 20615, 20626), 2 sandbox escapes (CVE-2026-20667, 20628), remote file write (CVE-2026-20660), and network interception (CVE-2026-20671). Source: Apple Security
- Apple releases comprehensive security updates across ALL platforms: iOS 26.3, iPadOS 26.3, macOS Tahoe 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, watchOS 26.3, tvOS 26.3, visionOS 26.3, Safari 26.3. CVE-2026-20700 patched in all OS-level updates. Source: Apple Security
- Threadlinqs Intelligence catalogs CVE-2026-20700 as TL-2026-0075. Google TAG attribution indicates commercial surveillance vendor exploit chain. Three-CVE chain pattern consistent with NSO Pegasus, Intellexa Predator, or similar mercenary spyware. Source: Threadlinqs
- Malwarebytes publishes detailed advisory on CVE-2026-20700, recommending immediate updates. Notes the three-CVE infection chain and warns about spyware/backdoor installation risk. Recommends Lockdown Mode for high-value targets. Source: Malwarebytes
- As of 2026-05-29, CVE-2026-20700 (Apple dyld memory corruption, Google TAG-discovered zero-click spyware chain) is fully patched in iOS/macOS 26.3 et al. released 2026-02-11 and remains in CISA KEV (added 2026-02-12, due 2026-03-05). It was a targeted commercial-spyware exploit, not mass exploitation; no continued exploitation, variants, or successor reported through NVD's 2026-03-25 update.
Sources cited for Apple Zero-Day CVE-2026-20700
- Malwarebytes: Apple patches zero-day flaw that could let attackers take control of devices
- Apple: About the security content of iOS 26.3 and iPadOS 26.3
- Apple: About the security content of macOS Tahoe 26.3
- Apple: About the security content of watchOS 26.3
- Apple: About the security content of tvOS 26.3
- Apple: About the security content of visionOS 26.3
- Apple: About the security content of Safari 26.3
- Apple Security Releases
- Google TAG: Commercial Surveillance Vendors — Buying Spying
Threats related to Apple Zero-Day CVE-2026-20700
Detection coverage for TL-2026-0075
As of 2026-02-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0075 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.