Exploitation Summary
EIP tracks 2 public exploits for CVE-2026-20660. PoCs published by XiaomingX, retX0.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2026-20660, which leverages a path traversal vulnerability in CFNetwork's NSGZipDecoder via malicious gzip FNAME headers. The exploit demonstrates arbitrary file write capabilities on vulnerable macOS Safari versions with auto-open enabled.
Description
A path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.5, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A remote user may be able to write arbitrary files.
Exploits (2)
This repository contains a functional proof-of-concept exploit for CVE-2026-20660, which leverages a path traversal vulnerability in CFNetwork's NSGZipDecoder via malicious gzip FNAME headers. The exploit demonstrates arbitrary file write capabilities on vulnerable macOS Safari versions with auto-open enabled.
This repository contains a functional proof-of-concept exploit for CVE-2026-20660, which leverages a path traversal vulnerability in CFNetwork's NSGZipDecoder via the gzip FNAME header. The exploit demonstrates arbitrary file write capabilities on vulnerable macOS Safari versions with auto-open enabled.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N