SECURITYCRITICALCVE-2026-20700

Apple Patches Actively Exploited iOS Zero-Day Used in Targeted Attacks

Apple has patched CVE-2026-20700, a memory corruption vulnerability in dyld used in 'extremely sophisticated' targeted attacks. Discovered by Google TAG,...

Dylan H.

Security Team

February 17, 2026
3 min read
Apple Patches Actively Exploited iOS Zero-Day Used in Targeted Attacks

Actively exploited

Reported as exploited in the wild (e.g. CISA KEV). Patch or mitigate immediately.

Affected Products

  • iOS before 26.3
  • iPadOS before 26.3
  • macOS Tahoe before 26.3
  • watchOS before 26.3
  • tvOS before 26.3
  • visionOS before 26.3

"Extremely Sophisticated" — Apple's Own Words

Apple has released emergency security updates across all platforms to patch CVE-2026-20700, a memory corruption vulnerability in dyld — Apple's dynamic linker. Apple described the attacks exploiting this vulnerability as "extremely sophisticated" — language the company rarely uses.

The vulnerability was discovered by Google's Threat Analysis Group (TAG), which specifically tracks nation-state actors and commercial spyware vendors.


Vulnerability Details

FieldDetails
CVECVE-2026-20700
Componentdyld (dynamic linker)
TypeMemory Corruption
SeverityCritical
ExploitationConfirmed in targeted attacks
Discovered ByGoogle Threat Analysis Group (TAG)
TargetSpecific individuals

Why dyld Is Critical

The dynamic linker (dyld) loads shared libraries when any application launches. It runs early in the startup chain with elevated privileges — a vulnerability here provides:

  • Code execution before security checks initialize
  • Universal exploitation — every app uses dyld
  • Privilege escalation from user-level to system-level

The Full Infection Chain

CVE-2026-20700 was part of a multi-stage infection chain that includes two WebKit zero-days patched in December 2025:

Stage 1: Initial Compromise (WebKit Zero-Days)
├── CVE-2025-14174 — WebKit type confusion (RCE)
└── CVE-2025-43529 — WebKit sandbox escape
 
Stage 2: Persistence & Escalation (dyld Zero-Day)
└── CVE-2026-20700 — dyld memory corruption
 
Stage 3: Payload Deployment
└── Full device compromise with persistent implant

This chain is consistent with commercial spyware attack patterns — carefully constructed to achieve zero-click or one-click full device compromise.


Who Is Being Targeted?

Apple's "specific targeted individuals" language historically aligns with:

  • Journalists investigating sensitive topics
  • Human rights activists and dissidents
  • Government officials and diplomats
  • Opposition politicians in authoritarian states

Google TAG's involvement strongly suggests a commercial spyware vendor or nation-state intelligence agency.


Patched Versions

PlatformFixed Version
iOS26.3
iPadOS26.3
macOS Tahoe26.3
watchOS26.3
tvOS26.3
visionOS26.3

How to Update

  1. iPhone/iPad: Settings > General > Software Update — Install iOS/iPadOS 26.3
  2. Mac: System Settings > General > Software Update — macOS Tahoe 26.3
  3. Apple Watch: Watch app > General > Software Update
  4. Apple TV: Settings > System > Software Updates

Defensive Recommendations

  1. Update all Apple devices immediately
  2. Enable Lockdown Mode for high-risk individuals (journalists, activists, executives)
  3. Enable Rapid Security Response for automatic critical patches
  4. Monitor for compromise indicators using tools like iVerify

Sources