Impact
The vulnerability is an out-of-bounds write that is fixed by removing the vulnerable code path. When a client connects to a malicious WebDAV server, the corrupted memory write can cause the associated application to terminate unexpectedly, resulting in a denial‑of‑service condition. This is an instance of an out‑of‑bounds write (CWE‑122).
Affected Systems
Apple macOS is impacted, with the fix applied in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Older releases remain vulnerable as the issue has not been patched there.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA KEV, so the current exploitation likelihood is unclear. The CVSS score is not provided, but the flaw is triggered by a remote connection to a malicious WebDAV server, implying a remote attack vector. Users running older macOS releases should prioritize updating to the fixed versions to mitigate the risk.
OpenCVE Enrichment