Junglewise Threat Intelligence

CVE-2026-43677: Apple macOS WebDAV out-of-bounds write

CVE-2026-43677 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

macOS includes system-level support for connecting to network file servers via WebDAV protocol. A vulnerability in WebDAV connection handling allows a malicious server to trigger an out-of-bounds memory write, causing applications to crash unexpectedly. While the immediate impact is denial of service, out-of-bounds write vulnerabilities can potentially be exploited for more severe attacks.

Technical details

An out-of-bounds write vulnerability exists in macOS WebDAV handling code. The vulnerability is triggered when a user or application connects to a malicious WebDAV server that sends specially crafted responses. The vulnerable code was removed in the patched versions rather than being hardened with bounds checking. The issue results in unexpected application termination (crash). The vulnerability requires user/application interaction to connect to a malicious WebDAV server; no remote code execution capability is currently documented. The issue is patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: patched: Fixes released in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7
  • 2026-09-14: disclosed

References

Related threats