CVE-2026-20660

HIGH

macOS Tahoe <26.3 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-20660. PoCs published by XiaomingX, retX0.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2026-20660, which leverages a path traversal vulnerability in CFNetwork's NSGZipDecoder via malicious gzip FNAME headers. The exploit demonstrates arbitrary file write capabilities on vulnerable macOS Safari versions with auto-open enabled.

Description

A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A remote user may be able to write arbitrary files.

Exploits (2)

github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-20660

This repository contains a functional proof-of-concept exploit for CVE-2026-20660, which leverages a path traversal vulnerability in CFNetwork's NSGZipDecoder via malicious gzip FNAME headers. The exploit demonstrates arbitrary file write capabilities on vulnerable macOS Safari versions with auto-open enabled.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: macOS Safari (before 26.3 patch line)
No auth needed
Prerequisites: Vulnerable macOS Safari version · Safari setting 'Open safe files after downloading' enabled · Network access to the target browser
devstral-2 · analyzed Mar 17, 2026 Full analysis →
nomisec WORKING POC
by retX0 · poc
https://github.com/retX0/CVE-2026-20660

This repository contains a functional proof-of-concept exploit for CVE-2026-20660, which leverages a path traversal vulnerability in CFNetwork's NSGZipDecoder via the gzip FNAME header. The exploit demonstrates arbitrary file write capabilities on vulnerable macOS Safari versions with auto-open enabled.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: macOS Safari (before 26.3 patch line)
No auth needed
Prerequisites: Vulnerable macOS Safari version · Safari setting 'Open safe files after downloading' enabled · Network access to the target browser
devstral-2 · analyzed Mar 16, 2026 Full analysis →

References (7)

Core 7
Core References
Release Notes, Vendor Advisory
https://support.apple.com/en-us/126346
Release Notes, Vendor Advisory
https://support.apple.com/en-us/126347
Release Notes, Vendor Advisory
https://support.apple.com/en-us/126348
Release Notes, Vendor Advisory
https://support.apple.com/en-us/126350
Release Notes, Vendor Advisory
https://support.apple.com/en-us/126353
Release Notes, Vendor Advisory
https://support.apple.com/en-us/126354

Scores

CVSS v3 7.5
EPSS 0.0077
EPSS Percentile 50.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (12)
Apple/iOS and iPadOS < 18.7.5
Apple/iOS and iPadOS < 26.3
apple/ipados < 18.7.5
apple/iphone_os < 18.7.5
apple/macos < 14.8.4
Apple/macOS < 14.8.4
Apple/macOS < 15.7.5
Apple/macOS < 26.3
apple/safari < 26.3
Apple/Safari < 26.3
... and 2 more
Published Feb 11, 2026
Tracked Since Feb 18, 2026