Back Scmagazine Apple fixes zero-day that exploited OS bug in open-source code
Apple on Feb. 11 patched an exploited zero-day that could let an attacker with memory write capability conduct an arbitrary code execution.
The large vendor said it was aware of a report that this issue may have been exploited in what it called an “extremely sophisticated” attack against “specific targeted individuals” on versions of iOS before iOS 26.
The patch for CVE-2026-20700 was fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3, and iPadOS 26.3.
Apple added that CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.
"Apple confirmed active exploitation of these vulnerabilities,” said Adam Boynton, senior enterprise strategy manager at Jamf. “For most organizations, there's a dangerous gap between when Apple ships a fix and when it actually protects your business — sometimes days, sometimes weeks, sometimes never.
Boynton said that gap represents measurable risk, the kind that appears in breach post-mortems and regulatory findings. Boynton explained that iOS 26.3 patches flaws that grant complete device control.
“Apple delivered the fix in days, but if your deployment relies on employees manually updating, you're running a beta test on your own security,” said Boynton. “In 2026, the question isn't whether you trust Apple's engineering. It's whether your deployment speed matches threat velocity."
Kelvin Lim, senior director, head of security engineering APAC at Black Duck, said this issue happened because a piece of open-source code in the Apple products had a security vulnerability. Lim explained that a single flaw in a shared component can affect every app or device that uses it.
“That’s what happened with this iOS 26.3 update,” said Lim. “A tiny part of the system, called the dyld, had a flaw. Since it’s used across iPhones, iPads, and Macs, the flaw put a lot of devices at risk."
Lim added that’s why many in the industry talk Software Bill of Materials (SBOMs) , a list of all the code ingredients in an app.
“Knowing what’s inside your software helps make sure the tools you rely on every day are safer,” said Lim.
Mayuresh Dani, security research manager at the Qualys Threat Research Unit, added that post-compromise, the sectors most at risk include government, defense, critical NGOs, large tech, energy, and finance, or executives with geopolitical exposure or those traveling to high-risk regions.
Dani said individuals and organizations in these group should do the following:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
