ZeroHour

Vulnerabilities

56 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-65374
Memory Corruption RCE via Malicious WebDAV Server in Apple macOS

CVE-2026-65374 is an out-of-bounds write (memory corruption) flaw in Apple macOS's handling of WebDAV connections, rated 8.8 (high) with network vector, low attack complexity, no privileges required, but user interaction required. It is triggered when a victim connects to an attacker-controlled WebDAV server — for example by clicking a webdav:// link or mounting an untrusted WebDAV share via Finder's 'Connect to Server' — and the malformed server responses corrupt memory in the WebDAV client code. Successful exploitation can yield arbitrary code execution with the privileges of the connecting user, impacting confidentiality, integrity, and availability. All Macs running macOS Sequoia before 15.8, macOS Tahoe before 26.7, and macOS Golden Gate before 27 are affected; Apple addressed the issue with improved validation. No public proof-of-concept is known and the flaw is not on the CISA KEV catalog, so there is no evidence of in-the-wild exploitation at this time.

Do: Patch to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27 (System Settings > Software Update), prioritizing fleets where users mount network shares. Advise users not to click webdav:// links or connect to WebDAV servers from untrusted sources, since the flaw requires user interaction. Egress/URL filtering can also block or flag webdav:// schemes and unexpected outbound WebDAV (TCP 80/443 with WebDAV methods) as a defense-in-depth measure.

8.8
group max
<1% PoC
  • Apple macOS Sequoia versions prior to 15.8
  • Apple macOS Tahoe versions prior to 26.7
  • Apple macOS Golden Gate versions prior to 27
masstens of millions of Macs (est. >1M, likely 10M–100M+ devices on unpatched macOS versions)
CVE-2026-65414
Out-of-Bounds Write in Apple iOS, iPadOS, macOS Enables Remote Code Execution

Apple patched a critical out-of-bounds write (CWE-787) memory-corruption flaw spanning nearly its entire operating-system lineup: iOS, iPadOS, macOS (Sequoia, Tahoe, Golden Gate), tvOS, visionOS, and watchOS. A remote attacker could trigger the flaw with no privileges and no user interaction (CVSS 3.1: 9.8, network vector, low complexity), causing unexpected app termination or potentially arbitrary code execution on the affected device. The advisory does not identify the vulnerable component or exact trigger, so defenders should assume any affected system is remotely attackable until patched. All users running iOS/iPadOS before 26.7, macOS Sequoia before 15.8, macOS Tahoe before 26.7, or pre-release tvOS/visionOS/watchOS builds older than 27 are affected. No public proof of concept exists, no exploitation in the wild is known, and the flaw is not on CISA's KEV list; fixes shipped in the listed updates.

Do: Update all Apple devices promptly: iPhones/iPads to iOS/iPadOS 26.7 or 27, Macs to macOS Sequoia 15.8, macOS Tahoe 26.7, or macOS Golden Gate 27, Apple TV to tvOS 27, Apple Watch to watchOS 27, and Vision Pro to visionOS 27. Enable automatic security updates and use MDM/inventory to find devices still on older OS trains. Given the 9.8 CVSS with no user interaction required, treat patching as high priority even though no exploitation has been observed.

9.8
group max
  • Apple iOS Prior to iOS 26.7 (26.x and earlier trains); fixed in iOS 26.7 and iOS 27
  • Apple iPadOS Prior to iPadOS 26.7 (26.x and earlier trains); fixed in iPadOS 26.7 and iPadOS 27
  • Apple macOS Sequoia Prior to 15.8; fixed in 15.8
  • +5 more
masspotentially 1+ billion devices (Apple's ~2.35 billion active-device install base, most on affected OS trains)
CVE-2026-64753
+1 in the same advisory: …84518
Permissions Flaw in Apple Safari and iOS/macOS Lets Web Content Leak User Data

CVE-2026-64753 is an improper privilege management (permissions) vulnerability in Apple's browser and operating system software that Apple fixed by removing the vulnerable code. It is triggered when a device processes maliciously crafted web content — typically a user visiting an attacker-controlled webpage — requiring user interaction but no privileges or attacker access to the device. Successful exploitation can disclose sensitive user information, reflected in a CVSS 3.1 base score of 6.5 (network vector, low attack complexity, high confidentiality impact, no integrity or availability impact). The flaw affects Safari and Apple's full OS lineup before the version 27 release wave — iOS, iPadOS, macOS Golden Gate, tvOS, visionOS, and watchOS — which shipped as part of a broad Apple update addressing 273 vulnerabilities. No public proof of concept is known, the issue is not on the CISA Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been confirmed.

Do: Update all Apple devices and browsers to the fixed releases: Safari 27, iOS/iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, and watchOS 27, prioritizing iPhones and Macs used for web browsing. Because exploitation requires a user to load malicious web content, advise users to avoid untrusted links until patched. IT admins should verify update compliance across managed device fleets and monitor for post-update browsing anomalies indicating possible information disclosure.

6.5
group max
  • Apple Safari versions prior to Safari 27
  • Apple iOS versions prior to iOS 27
  • Apple iPadOS versions prior to iPadOS 27
  • +4 more
masslikely >1 billion users/devices potentially exposed before patching