CVE-2026-20652

Published: March 20, 2026Last modified: April 27, 2026

Description

The issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.3, iOS 18.7.5 and iPadOS 18.7.5, visionOS 26.3, iOS 26.3 and iPadOS 26.3, Safari 26.3. A remote attacker may be able to cause a denial-of-service.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Liberica JDK8jdk-fullFixed (8u492+9)
jre-fullFixed (8u492+9)
11jdk-fullFixed (11.0.31+11)
jre-fullFixed (11.0.31+11)
17jdk-fullFixed (17.0.19+11)
jre-fullFixed (17.0.19+11)
21jdk-fullFixed (21.0.11+11)
jre-fullFixed (21.0.11+11)
25jdk-fullFixed (25.0.3+11)
jre-fullFixed (25.0.3+11)
26jdk-fullFixed (26.0.1+10)
jre-fullFixed (26.0.1+10)

References

Published BELL-SAs

ON THIS PAGE