The images in this article were generated with artificial intelligence. How we publish
Apple has published a series of security patches to correct a zero-day vulnerability that, according to the company, was used in an "extremely sophisticated attack" directed against specific individuals. The problem, identified as CVE-2026-20700, affects the component known as dyll - the Dynamic Link Editor using iOS, iPhadOS, macOS, tvOS, watchOS and visionOS - and would allow the execution of arbitrary code if an attacker achieves the ability to write in the memory of the device.
In its newsletter, Apple warns that vulnerability could be exploited by an opponent with access to memory writing to run unauthorized code on the affected devices. The company also indicates that this finding is related to two errors corrected last December, those recorded as CVE-2025-14174 and CVE-2025-43529 and that all of them appear to be linked to the same series of targeted incidents. The official note is available on the Apple support website: Apple Support - Security Update.

Google, through its Threat Analysis Group, was the one who detected the CVE-2026-20700 failure, according to Apple, although the company has not provided technical details about the exact operating mechanism or the initial vector of the attack. The participation of teams such as the Google Threat Analysis Group It usually indicates that the activity was highly directed and well orchestrated, focused on high-risk objectives.
Understanding why dyll is relevant helps to value gravity. Dyld is the dynamic charger that links libraries and executable on Apple platforms; any failure in this component can open the door to which malicious code is injected and run at a very low level of the system. Apple has documentation for developers about dyll that explains its function and why it is so critical: Dyld documentation. For the security community, the vulnerabilities that allow arbitrary code execution are among the most worrying, because they can be used to install spyware, steal data or take remote control of the device.
Apple has solved the problem in iOS 18.7.5, iPadOS 18.7.5, mac Tahoe 26.3, tvOS 26.3, watchOS 26.3 and visionOS 26.3. Among the devices cited as affected are modern iPhone and iPad models - such as the iPhone 11 forward and several recent generations of iPad Pro, iPad Air and iPad mini - as well as Mats that run Tahoe macos. If you use any of these equipment, it is important to update as soon as possible.
Although Apple indicates that the operation was selective - targeted at specific individuals in previous versions of iOS 26 - the recommendation for users is simple and direct: install available updates as soon as possible. Updating the operating system immediately reduces the exposure window to this type of defect. If you need step-by-step instructions, Apple maintains a public guide on how to update your devices here: How to update iPhone, iPad or iPod touch.
This patch represents the first one-day zero arrangement Apple has made public in 2025; by 2025 the company had already corrected several critical vulnerabilities, accumulating seven zero-day patches throughout the year. This pattern highlights two complementary facts: on the one hand, that sophisticated attackers continue to develop and exploit complex failures; on the other, that a collaboration between researchers and large platforms (such as the one reported between Google and Apple) can detect and mitigate threats before they spread massively.

For private users and system administrators there are some good practices that go beyond applying the patch. Maintaining up-to-date and encrypted backup, reviewing application permissions and minimizing the installation of dubious software help reduce the attack surface. In business environments, detection and response controls, network segmentation and mobile device management policies expand protection against targeted attacks.
Apple has not yet revealed any more information on how the exploitation was carried out or on who the targets were, which is common when investigations remain open or when public revelations could help attackers refine their techniques. For those who want to deepen in the context of vulnerabilities and outreach programmes, the CVE initiative and its general explanation can serve as a starting point: What is CVE?.
In short, although the threat described by Apple was directed and does not indicate a massive campaign, the combination of a dynamic charger failure and the possibility of arbitrary code execution requires not to relax. The most effective and accessible measure for any user is to install the updates of iOS, iPadOS, macOS and other systems Apple has published and maintain digital safety habits that limit the impact of future attacks.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...