Apple fixes CVE-2026-20700 used in targeted attacks

Apple has released security updates for several products addressing CVE-2026-20700. The vulnerability lets an attacker who can already write to memory execute arbitrary code. It was originally discovered by Google's Threat Analysis Group and is confirmed to have been exploited by a commercial surveillance vendor against specific individuals such as journalists and activists. According to Google Threat Intelligence Group, the flaw formed part of a three-stage attack chain alongside two older vulnerabilities, with CVE-2026-20700 used for privilege escalation on the compromised device.

What this means for your organisation

Commercial surveillance attacks are targeted and reach few people, but those people hold access and insight: executives, legal, communications and anyone handling sensitive matters. For most organisations this is chiefly a reminder that mobile devices are a full part of the attack surface and need the same patching discipline as everything else.

Berigo recommends

  • Deploy Apple's updates across all managed devices and follow up the ones that have not applied them.
  • Identify who in the organisation is genuinely exposed to targeted surveillance and set stricter device requirements for them.
  • Enable Apple's enhanced protection mode for the most exposed users, and explain what it means day to day.
  • Include mobile devices in the incident response plan: who is alerted, what is preserved, how the device is replaced.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch