ZeroHour

CVE-2026-43677

mass

Out-of-Bounds Write in Apple macOS WebDAV Client

CVSS 3.1
6.5 medium
EPSS
Published
()
Modified
AI analysis

CVE-2026-43677 is an out-of-bounds write vulnerability in Apple's WebDAV connectivity code on macOS, fixed by removing the vulnerable code entirely. It is triggered when a user connects their Mac to a malicious WebDAV server, such as by mounting an untrusted WebDAV share via Finder. Apple describes the practical impact as unexpected app termination, though out-of-bounds writes are a memory-corruption class that can sometimes carry greater consequences than denial of service. All Macs running macOS Sequoia before 15.8, macOS Tahoe before 26.7, or macOS Golden Gate before 27 are affected until patched. No public proof of concept exists, the flaw is not on the CISA KEV list, and no exploitation has been reported; Apple shipped the fix in its September 'Updates Everything' release wave.

What to do: Patch to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (or later), which Apple released in its September update wave. Until patched, advise users not to mount or connect to WebDAV servers they do not explicitly trust, and review existing WebDAV mounts in Finder/Connect to Server for anything unexpected. No workaround beyond OS updating is documented, since Apple fixed this by removing the vulnerable code.

Affected
Apple macOS Sequoiaprior to 15.8
Apple macOS Tahoeprior to 26.7
Apple macOS Golden Gateprior to 27
Estimated exposure
massOn the order of 100 million+ Macs (any unpatched macOS Sequoia, Tahoe, or Golden Gate system) — Apple's Mac installed base is publicly estimated at well over 100 million active devices, and every Mac on an unfixed version carries the vulnerable WebDAV code, though actual attack surface requires the user to connect to an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious WebDAV server may lead to unexpected app termination.

Vendors
apple
Products
macos
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

Apple Updates Everything, (Mon, Sep 14th)

Apple patched a record 261 vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS 27, and other platforms, with none flagged as exploited.

Apple's annual OS update shipped iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27, and visionOS 27 plus bug-fix releases for the 26 and 15 branches, fixing a record 261 vulnerabilities. Notable issues include multiple kernel flaws allowing root privilege escalation (CVE-2026-43689, CVE-2026-43691, CVE-2026-43698, CVE-2026-43786), remote code execution in CUPS (CVE-2026-43692), kernel memory corruption via malicious NFS servers (CVE-2026-43686, CVE-2026-43687), and WebKit memory corruption from crafted web content (CVE-2026-43715). No vulnerabilities are labeled as actively exploited, and Apple does not assign per-CVE severities. Users report iOS 26.7 being downloaded when iOS 27 is intended, and tools like Little Snitch and BlockBlock need updates before upgrading to macOS 27.

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

Apple's record patch cycle fixes 260+ CVEs across iOS 27 and macOS 27, including CUPS remote code execution, with no active exploitation reported.

Apple patched more than 260 CVEs across its operating systems and software, its largest single patch cycle ever, with iOS 27 fixing 122 flaws and macOS 27 Golden Gate fixing 204. Notable bugs include CVE-2026-43692, a CUPS validation issue allowing remote code execution, and CVE-2026-43689, an iOS privilege-escalation flaw granting root access. Ten CVEs were credited to AI-assisted bug hunting, including CVE-2026-65410 and CVE-2026-65409 found by Calif with Claude and Anthropic Research. None of the vulnerabilities are listed as actively exploited.