Vulnerability record · CVE-2006-0395 · published 5 August 2006
CVE-2006-0395: Apple Mail Download Validation fails to flag unsafe attachment types
Apple · Mac Os X
The Download Validation feature in Mail on Mac OS X 10.4 does not correctly recognize attachment file types, so it fails to warn the user about unsafe types. Because the warning is missing, a user can be tricked into opening a crafted attachment that leads to code execution. The record does not specify which file types or versions are affected beyond Mac OS X 10.4 and Server.
Description
The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user-assisted remote attackers to execute arbitrary code via crafted file types.
AV:N/AC:H/Au:N/C:P/I:P/A:P
Automated analysis
medium priorityRequires user interaction and a specific legacy OS, but a missing security warning enables code execution and EPSS is high.
What it is
The Download Validation feature in Mail on Mac OS X 10.4 does not correctly recognize attachment file types, so it fails to warn the user about unsafe types. Because the warning is missing, a user can be tricked into opening a crafted attachment that leads to code execution. The record does not specify which file types or versions are affected beyond Mac OS X 10.4 and Server.
Impact
An attacker can execute arbitrary code in the context of the user who opens the crafted attachment. This gives code execution on the victim's system without a memory-corruption exploit, relying instead on the missing warning.
Attack surface
Reached remotely by sending an email with a crafted attachment to a Mail user; the CVSS vector AV:N/AC:H/Au:N indicates network delivery with no authentication, but successful exploitation requires the user to open the attachment.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit or proof-of-concept, though EPSS is high at 0.55376 (99th percentile). The record does not confirm public exploit code.
What to do
- Apply the Apple security update referenced in Apple article 303382 (Mac OS X 10.4 era) or upgrade to a supported macOS release.
- Disable automatic opening of attachments and configure Mail to not render or launch attachment content.
- Train users not to open unexpected attachments and to verify sender intent out of band.
- Block or quarantine risky attachment types at the mail gateway where feasible.
Detection
- Monitor Mail application launches of processes spawned from attachment paths or temporary download directories.
- Alert on execution of files originating from Mail's attachment storage locations.
- Review mail gateway logs for attachment types that bypass or evade Download Validation warnings.
- Correlate user reports of unexpected attachment behavior with process creation events on macOS endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-0395 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-0395), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.