Apple CFNetwork Path Handling Vulnerability Allowing Arbitrary File Writing

Vulnerability

A path handling vulnerability in the CFNetwork component of multiple Apple products, including macOS Tahoe 26.3, macOS Sonoma 14.8.4, iOS 18.7.5, iPadOS 18.7.5, and visionOS 26.3, has been identified. This vulnerability allows a remote user to write arbitrary files on the affected system. The issue arises from improper path validation, which could be exploited to manipulate file writing processes.

Impact

Exploitation of this vulnerability could lead to unauthorized file writing on the affected device, potentially allowing for the introduction of malicious files or the modification of existing files in a way that could be harmful.

Added: Feb 12, 2026, 12:00 AM
Updated: Feb 12, 2026, 12:00 AM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
3.3
exploitability
4.7
remediation
7.7
relevance
3.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.