Exploitation Summary
EIP tracks 2 public exploits for CVE-2026-20637. PoCs published by zeroxjf, enfilade-labs.
AI-analyzed exploit summary The repository contains a functional proof-of-concept exploit for CVE-2026-20637, a use-after-free vulnerability in AppleSEPKeyStore. The exploit triggers a kernel panic by racing IOConnectCallMethod and IOServiceClose operations, demonstrating the vulnerability in iOS/macOS versions 26.1-26.2.
Description
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to cause unexpected system termination.
Exploits (2)
The repository contains a functional proof-of-concept exploit for CVE-2026-20637, a use-after-free vulnerability in AppleSEPKeyStore. The exploit triggers a kernel panic by racing IOConnectCallMethod and IOServiceClose operations, demonstrating the vulnerability in iOS/macOS versions 26.1-26.2.
This repository contains a functional proof-of-concept exploit for CVE-2026-20637, a use-after-free vulnerability in AppleSEPKeyStore. The exploit triggers a kernel panic by racing IOConnectCallMethod and IOServiceClose operations, demonstrating the vulnerability in iOS and macOS versions 26.1 to 26.2.
References (8)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H