Researchers disclosed the first public bypass of Apple Memory Integrity Enforcement (MIE) on macOS 26.4.1 by chaining two vulnerabilities: CVE-2026-64704 in SMBClient and CVE-2026-64699 in webdavfs. The SMB flaw is a type confusion issue triggered when a macOS client connects to a malicious SMB server, causing the kernel to reinterpret a Resolve ID context as a lease context and misuse attacker-influenced kernel pointers. The WebDAV flaw is a kernel memory disclosure bug triggered by a crafted HTTP 206 response from a malicious WebDAV server, leaking uninitialized kernel memory to userspace.
The researchers said the combined exploit chain produces arbitrary kernel read/write primitives and ultimately kernel code execution, allowing an unprivileged user to escalate privileges to root despite Apple’s layered kernel protections. Apple has patched both issues in macOS 26.6, and the disclosure was accompanied by a public exploit-development challenge and notice of a planned Black Hat USA presentation detailing the technique.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The disclosure announced a full presentation at Black Hat USA scheduled for August 5, 2026. The talk would cover the two vulnerabilities and the Apple MIE bypass technique.
The Calif post launched a public exploit-development challenge based on CVE-2026-64704 and CVE-2026-64699. The challenge centered on exploiting the two bugs used in the Apple MIE bypass chain.
On July 27, 2026, Calif Global published details of two macOS vulnerabilities chained to produce the first public bypass of Apple MIE on macOS 26.4.1. The disclosure explained that the SMBClient type confusion and WebDAV kernel memory disclosure together enabled kernel read/write primitives, kernel code execution, and escalation to root.
Apple addressed CVE-2026-64704 in SMBClient and CVE-2026-64699 in webdavfs in macOS 26.6. The two flaws could be chained to bypass Apple Memory Integrity Enforcement and achieve local privilege escalation to root.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.