Trending Topics

Apple confirms “forever day” vulnerability hidden in iPhones since iOS 1
All vulnerabilities are not the same. Heck, that much is a given as any cybersecurity professional worth their security salt will testify. That’s why we have a little something called patch prioritisation, based upon risk to the organisation.
Some vulnerability alerts carry a lot more weight than others: your honour, I would like to submit zero-days into evidence. But wait, what if a vulnerability, already being used in very real-world attacks, is a “forever day”?
Apple has just released iOS 26.3 without much fanfare, but that doesn’t mean you can take your time updating your iPhone to it. If you value your security and your data privacy, then you must take CVE-2026-20700 very seriously indeed.
An Apple spokesperson said that the smartphone giant “is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26”.
Now, as a veteran cybersecurity nerd with the scars to prove it, I can tell you that “extremely sophisticated attack against specific targeted individuals” is, more often than not, shorthand for spyware. Which would make sense in this case. After all, iOS 26.2 patched two vulnerabilities, CVE-2025-14174 and CVE-2025-43529, discovered in collaboration with Google’s Threat Analysis Group, using the same “extremely sophisticated” language and widely reported as being spyware-related.
Apple’s forever day vulnerability
What really caught my attention, however, was that this particular vulnerability affects all versions of the iPhone operating system before iOS 26.
“Because this flaw affects all prior versions of iOS,” said Brian Milbier, Deputy Chief Information Security Officer at Huntress, “it has likely been hiding in the system’s foundation since iOS 1.”
In his best Marks & Spencer advert voice, well, I like to think so anyway, Milbier warned: “This isn’t just a standard patch; it’s a fix for a ‘forever day’ vulnerability.”
Apple has said that CVE-2026-20700 is a dyld vulnerability (Apple’s dynamic linker) that can provide “an attacker with memory write capability” and the potential “to execute arbitrary code”.
It has also stated that this CVE was issued in response to the same Google TAG report responsible for the confirmation of CVE-2025-14174 and CVE-2025-43529.
“Think of dyld as the doorman for your phone,” Milbier explained, adding that “every single app that wants to run must first pass through this doorman to be assembled and given permission to start.” The forever day vulnerability tricks the doorman into handing over the keys before any security checks have commenced.
What you need to now…
Milbier told me that “it is critical that people don’t avoid installing new updates and apply these fixes immediately”. He’s not wrong about the potential dangers posed by such a vulnerability, but I will remain calm and point you, dear reader, at my previous statement that patch prioritisation should be based upon risk to the organisation.
Bearing in mind that the in-the-wild exploits have been, according to Google and Apple, against “specific targeted individuals,” this does not appear to be a scattergun, indiscriminate, attack campaign.
That said, I do recommend updating as soon as possible. Why take the risk of falling victim, after all?
Of course, if you’re using devices that can’t update to iOS 26.3 then you have a big decision to make as these won’t be protected. As Milbier concluded: “A ‘forever day’ vulnerability stays open forever on devices that Apple is no longer updating.”
