CVE-2026-65374
Apple · macOS
A memory corruption vulnerability in macOS allows unauthenticated attackers to achieve remote code execution by enticing a user to connect to a malicious WebDAV server.
Executive summary
A critical memory corruption vulnerability in macOS allows for remote code execution when a user connects to a malicious WebDAV server.
Vulnerability
This is a memory corruption flaw triggered by improper input validation during WebDAV server interactions. The vulnerability allows an unauthenticated attacker to execute arbitrary code on the host system if a user is coerced into connecting to a malicious WebDAV endpoint.
Business impact
Successful exploitation of this vulnerability enables an attacker to execute arbitrary code with the privileges of the logged-in user. This could lead to a full system compromise, unauthorized access to sensitive local data, and potential lateral movement within the network. Given the CVSS score of 8.8, this flaw represents a significant risk to organizational security and data integrity.
Remediation
Immediate Action: Update macOS systems immediately to version 15.8, 26.7, or 27 to apply the necessary memory validation patches.
Proactive Monitoring: Review system and network logs for unusual outbound connections to WebDAV services or unauthorized attempts to mount remote filesystems.
Compensating Controls: Implement network-level egress filtering to restrict unauthorized connections to untrusted or external WebDAV servers.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub.
Analyst recommendation
The potential for remote code execution via a simple user interaction makes this a high-severity threat. Administrators must prioritize the deployment of the vendor-provided updates to the affected macOS versions. Failure to patch these systems leaves endpoints vulnerable to exploitation through malicious network interactions.
More Apple CVEs all →
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written