Input validation error in macOS - CVE-2026-20650
Published: February 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in Bluetooth. A remote attacker in a privileged network position can send specially crafted Bluetooth packets to the system and perform a denial of service (DoS) attack.
Affected software
visionOS
watchOS
tvOS
iPadOS
Apple iOS
How to mitigate CVE-2026-20650
visionOS - update to 26.3
watchOS - update to 26.3 23S620
tvOS - update to 26.3 23K620
iPadOS - update to 26.3 23D127
Apple iOS - update to 26.3 23D127