Impact
An attacker can exploit a memory corruption flaw in macOS that is triggered by connecting to a specially crafted WebDAV server. The flaw can lead to arbitrary code execution in the context of the affected system, allowing full compromise of confidentiality, integrity, and availability when the vulnerability is successfully macOS is affected. The vulnerability exists in macOS Golden Gate 27,.8, and macOS Tahoe 26.7 and earlier revisions.
Affected Systems
The memory corruption flaw was present in macOS releases prior to the following fixes: macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Systems running any of those earlier releases of macOS – including Golden Gate, Sequoia or Tahoe – are potentially affected. No other Apple products are listed as impacted in the advisory.
Risk and Exploitability
The EPSS score is less than 1%, indicating a low exploitation probability, and the flaw is not listed in the CISA KEV catalog, indicating no publicly known exploits at this time. Nevertheless, the vulnerability permits remote code execution over a network connection to a malicious WebDAV server, making the potential impact high. A successful exploitation could hand an attacker full control of the operating system, compromising all stored data and system functions.
OpenCVE Enrichment