Junglewise Threat Intelligence

CVE-2026-65374: Apple macOS WebDAV memory corruption remote code execution

CVE-2026-65374 · Severity: high · CVSS 8.8 · Published 2026-09-14

Technologies: Apple macOS Golden Gate, Apple macOS Tahoe. Vendors: Apple.

Executive brief

macOS includes file-sharing protocols like WebDAV that allow users to connect to remote servers for collaborative work and file access. An attacker operating a malicious WebDAV server can exploit a memory corruption flaw to execute arbitrary code on a victim's computer with no user interaction beyond the normal connection action. This could lead to complete system compromise including data theft, malware installation, and lateral movement within corporate networks.

Technical details

The vulnerability is a memory corruption issue in macOS's WebDAV client implementation, addressable through improved validation of untrusted server responses. The attack vector is network-based: a user or automated process connecting to a malicious WebDAV server can be exploited without requiring any special privileges or user interaction beyond initiating the connection. An attacker can achieve arbitrary code execution in the context of the connecting process or user. The flaw has been patched in macOS Golden Gate 27, macOS Sequoia 15.8, and macOS Tahoe 26.7; users should apply these updates immediately.

Affected products

  • Apple macOS Golden Gate before 27
  • Apple macOS Sequoia before 15.8
  • Apple macOS Tahoe before 26.7

Timeline

  • 2026-09-14: disclosed: Published in NVD
  • 2026-09-14: patched: Fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7

References

Related threats