5.5
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Description
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3. A user with Live Caller ID app extensions turned off could have identifying information leaked to the extensions.
Basic Information
ID
CVE-2026-20638
Source
apple
Published
Feb 11, 2026 at 22:58
Modified
Feb 12, 2026 at 19:34
Affected Product
Vendor
Apple
Product
iOS and iPadOS
Version
unspecified
Affected Versions
Apple iOS and iPadOS unspecified