Apple patches critical iOS zero-day vulnerability exploited in targeted attacks
By
beardyw
Pulled from the oven just right. Trustworthy, fact-dense, deeply satisfying.
Summary
Apple has patched a critical zero-day vulnerability (CVE-2026-20700) affecting every iOS version since 1.0, discovered by Google's Threat Analysis Group. The flaw in Apple's dynamic linker (dyld) allows attackers with memory write capability to execute arbitrary code. Apple confirmed the vulnerability was exploited in targeted attacks against specific individuals, describing it as part of an 'extremely sophisticated attack' likely involving commercial spyware. The patch addresses a decade-old security issue that had persisted across all iOS versions.
Key quotes
· 4 pulledApple patched a zero-day vulnerability affecting every iOS version since 1.0, used in what the company calls an 'extremely sophisticated attack' against targeted individuals.
CVE-2026-20700, discovered by Google's Threat Analysis Group, affects dyld - Apple's dynamic linker - and allows attackers with memory write capability to execute arbitrary code.
Apple said the flaw was exploited in the wild and may have been part of an exploit chain.
Flaw abused 'in an extremely sophisticated attack against specific targeted individuals'
You might also wanna read
Apple adds new CVE vulnerability details to macOS, iOS, iPadOS, visionOS, and watchOS security pages
Apple has updated the security content pages for several of its operating system releases — including macOS Sonoma, iOS 18.7, iPadOS 18.7, v
9to5mac.com·5d ago
Google detects and blocks first known AI-assisted zero-day exploit
Google's Threat Intelligence Group has detected and stopped what it says is the first known zero-day exploit developed with AI assistance. T

GitHub patches critical remote code execution vulnerability in under six hours after AI-assisted discovery
GitHub patched a critical remote code execution vulnerability in under six hours last month. The flaw, discovered by Wiz Research using AI m
Microsoft criticizes uncoordinated disclosure of six zero-day vulnerabilities
Microsoft has criticized the irresponsible disclosure of six zero-day vulnerabilities in its products, named BlueHammer, GreenPlasma, MiniPl
