The Fruity Cargo Cult Apple has issued fixes after a possibly ancient zero-day began being used in the wild.
According to SecurityWeek, the hole is tracked as CVE-2026-20700; it is a memory-corruption flaw that could enable arbitrary code execution. It hits dyld, the Dynamic Link Editor that loads dynamic libraries and links apps to system frameworks.
Apple said: “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26.”
However, the problem may have persisted for a long time because dyld is legacy plumbing, and one security researcher believes the door has been “unlocked for over a decade.”
Job’s Mob said the exploitation is linked to attacks involving CVE-2025-14174 and CVE-2025-43529, two WebKit zero-days it patched in December 2025. A week before Job’s Mob moved this time, Google rolled out Chrome fixes for CVE-2025-14174 while it still lacked a CVE label.
The three bugs were identified by Job’s Mob’s security team and Google’s Threat Analysis Group, and the write-ups point to commercial spyware-grade abuse. On 11 February 2026, Apple said the CVE-2026-20700 patch is available in iOS 26.3, iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, watchOS 26.3, and visionOS 26.3.
The iOS and iPadOS updates fix nearly 40 vulnerabilities, while macOS Tahoe gets more than 50 security patches. The list includes information exposure, denial-of-service, arbitrary file write, privilege escalation, network traffic interception, sandbox escape, and code execution.
Older hardware is not spared, with iOS 18.7.5 and iPadOS 18.7.5, macOS Sequoia 15.7.4 and macOS Sonoma 14.8.4 also landing. Each bundle fixes more than three dozen vulnerabilities, which is a cheery reminder that “legacy support” still means plenty of sharp edges.
Safari 26.3 was released the same day, with eight fixes, including six for WebKit. Job’s Mob says update quickly, while some reporting claims this dyld weakness may have been sitting around for years and only got fixed once commercial hacking made it too noisy to ignore.







