CVE-2026-65374

Apple · macOS

A memory corruption vulnerability in macOS allows unauthenticated attackers to achieve remote code execution by enticing a user to connect to a malicious WebDAV server.

Executive summary

A critical memory corruption vulnerability in macOS allows for remote code execution when a user connects to a malicious WebDAV server.

Vulnerability

This is a memory corruption flaw triggered by improper input validation during WebDAV server interactions. The vulnerability allows an unauthenticated attacker to execute arbitrary code on the host system if a user is coerced into connecting to a malicious WebDAV endpoint.

Business impact

Successful exploitation of this vulnerability enables an attacker to execute arbitrary code with the privileges of the logged-in user. This could lead to a full system compromise, unauthorized access to sensitive local data, and potential lateral movement within the network. Given the CVSS score of 8.8, this flaw represents a significant risk to organizational security and data integrity.

Remediation

Immediate Action: Update macOS systems immediately to version 15.8, 26.7, or 27 to apply the necessary memory validation patches.

Proactive Monitoring: Review system and network logs for unusual outbound connections to WebDAV services or unauthorized attempts to mount remote filesystems.

Compensating Controls: Implement network-level egress filtering to restrict unauthorized connections to untrusted or external WebDAV servers.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept repository exists on GitHub.

Analyst recommendation

The potential for remote code execution via a simple user interaction makes this a high-severity threat. Administrators must prioritize the deployment of the vendor-provided updates to the affected macOS versions. Failure to patch these systems leaves endpoints vulnerable to exploitation through malicious network interactions.

More Apple CVEs all →

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written

Sources