An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, macOS Tahoe 26.3, macOS Sonoma 14.8.4, visionOS 26.3. Processing a maliciously crafted USD file may lead to unexpected app termination.
References
| Link | Resource |
|---|---|
| https://support.apple.com/en-us/126347 | Release Notes Vendor Advisory |
| https://support.apple.com/en-us/126348 | Release Notes Vendor Advisory |
| https://support.apple.com/en-us/126350 | Release Notes Vendor Advisory |
| https://support.apple.com/en-us/126353 | Release Notes Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-26-176/ |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-02-11 23:16
Updated : 2026-03-16 14:18
NVD link : CVE-2026-20616
Mitre link : CVE-2026-20616
CVE.ORG link : CVE-2026-20616
JSON object : View
Products Affected
apple
- macos
- visionos
- ipados
- iphone_os
CWE
CWE-787
Out-of-bounds Write
