CVE-2026-20677
A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and i
CVSS
9.0
Crítico
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Publicado: 11 feb 2026 · Última mod.: 21 ago 2026 · CWE-362 · CWE-367
0.3%EPSS · 30 días0.3%
2026-08-082026-09-05
A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox restrictions.
- support.apple.comhttps://support.apple.com/en-us/126346
- support.apple.comhttps://support.apple.com/en-us/126347
- support.apple.comhttps://support.apple.com/en-us/126348
- support.apple.comhttps://support.apple.com/en-us/126349
- support.apple.comhttps://support.apple.com/en-us/126350
- support.apple.comhttps://support.apple.com/en-us/126353
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-769255.8 MED0.8%
——0A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the `Deploy()` function. An attacker can exploit this timing window to redirect symlinks to arbitrary files, potentially leading to unauthorized file manipulation or information disclosure.2dCVE-2026-857043.7 BAJ19.6%
——6A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the component Jailbreak Mode. The manipulation results in race condition. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit has been released to the public and may be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. This vulnerability only affects products that are no longer supported by the maintainer.2dCVE-2026-856395.6 MED12.8%
——4A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core/user.py of the component Telemetry Endpoint. Such manipulation of the argument vId leads to race condition. The attack can be executed remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.2dCVE-2026-185674.4 MED0.1%
——0IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.2dCVE-2026-45197—1.5%
——0Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised GPU memory.
The firmware uses data provided by the Guest VM to set up accesses to memory. It validated this before use, but a TOCTOU bug was present which allowed the earlier check results to be invalidated.2dCVE-2026-850457.5 ALT15.3%
——5Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)2d