Vulnerability Details CVE-2026-43677
An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. Connecting to a malicious WebDAV server may lead to unexpected app termination.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 6.5%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-43677
-
cpe:2.3:o:apple:macos:26.0
-
cpe:2.3:o:apple:macos:26.0.0
-
cpe:2.3:o:apple:macos:26.1
-
cpe:2.3:o:apple:macos:26.2
-
cpe:2.3:o:apple:macos:26.3
-
cpe:2.3:o:apple:macos:26.3.1
-
cpe:2.3:o:apple:macos:26.4
-
cpe:2.3:o:apple:macos:26.5
-
cpe:2.3:o:apple:macos:26.5.2
-
cpe:2.3:o:apple:macos:26.6.1