Description
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious WebDAV server may result in code execution.
Published: 2026-09-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An attacker can exploit a memory corruption flaw in macOS that is triggered by connecting to a specially crafted WebDAV server. The flaw can lead to arbitrary code execution in the context of the affected system, allowing full compromise of confidentiality, integrity, and availability when the vulnerability is successfully macOS is affected. The vulnerability exists in macOS Golden Gate 27,.8, and macOS Tahoe 26.7 and earlier revisions.

Affected Systems

The memory corruption flaw was present in macOS releases prior to the following fixes: macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7. Systems running any of those earlier releases of macOS – including Golden Gate, Sequoia or Tahoe – are potentially affected. No other Apple products are listed as impacted in the advisory.

Risk and Exploitability

The EPSS score is less than 1%, indicating a low exploitation probability, and the flaw is not listed in the CISA KEV catalog, indicating no publicly known exploits at this time. Nevertheless, the vulnerability permits remote code execution over a network connection to a malicious WebDAV server, making the potential impact high. A successful exploitation could hand an attacker full control of the operating system, compromising all stored data and system functions.

Generated by OpenCVE AI on September 20, 2026 at 20:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade macOS to the latest release that includes the fix: macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, or later.
  • If an upgrade is not immediately possible, block or disable WebDAV connections to untrusted hosts by configuring firewall rules or network policies to restrict the DAV protocol.
  • Ensure third-party applications that interact with WebDAV implement proper bounds checking to prevent memory corruption, addressing CWE-787 vulnerabilities.
  • Monitor system logs for unexpected WebDAV traffic or abnormal interim security guidance.

Generated by OpenCVE AI on September 20, 2026 at 20:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption in macOS WebDAV Client Allowing Remote Code Execution

Wed, 16 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption via Malicious WebDAV Causing Code Execution on macOS

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption via Malicious WebDAV Causing Code Execution on macOS
Weaknesses CWE-787

Tue, 15 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Vendors & Products Apple
Apple macos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious WebDAV server may result in code execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-16T03:56:18.111Z

Reserved: 2026-07-22T00:46:16.023Z

Link: CVE-2026-65374

cve-icon Vulnrichment

Updated: 2026-09-15T14:28:49.102Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:21.810

Modified: 2026-09-16T04:18:38.750

Link: CVE-2026-65374

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T20:45:03Z

Weaknesses