- Description
- An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
- Source
- product-security@apple.com
- NVD status
- Analyzed
- Products
- ipados, iphone_os, macos
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Apple Multiple Products Out-of-Bounds Write Vulnerability
- Exploit added on
- Sep 29, 2026
- Exploit action due
- Oct 2, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-787
- Hype score
- Not currently trending
🚨 CVE-2026-86950 — HIGH — actively exploited per CISA KEV Apple Multiple Products CVSS 8.8 | EPSS 1% #Apple #CVE https://t.co/AFzyJmqwal
@threatpodium
29 Sept 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Vulnerability · Exploited in the wild CVE-2026-86950 (Apple · CoreGraphics) An out‑of‑bounds write in CoreGraphics (CVE-2026-86950) can allow arbitrary code execution; Apple issued patches on Sept 28 and CISA added it to KEV with… Full report and PDF: https://t.co/zsu8q
@gettransilience
29 Sept 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-86950 has been published. Apple Multiple Products Out-of-Bounds Write Vulnerability. Add it to your patching queue if applicable. Details: https://t.co/c5dLy169H2 #CVE #InfoSec #VulnMgmt
@Prateektomar
29 Sept 2026
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ CYBER BULLETIN | 2026/09/29 🚨 1. Apple patches CoreGraphics zero-day exploited in targeted attacks CVE-2026-86950 is an out-of-bounds write in CoreGraphics that lets a crafted file trigger arbitrary code execution. Apple says it may have been used in extremely https
@FrontieraTechIT
29 Sept 2026
105 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🛡️ CYBER BULLETIN | 2026/09/29 🚨 1. Apple patches CoreGraphics zero-day exploited in targeted attacks CVE-2026-86950 is an out-of-bounds write in CoreGraphics that lets a crafted file trigger arbitrary code execution. Apple says it may have been used in extremely https
@FrontieraTechIT
29 Sept 2026
157 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Patch Now | September 29, 2026 Bringing these vulnerabilities to your attention: - Citrix NetScaler: two zero-days (CVE-2026-88771, CVE-2026-88772) - Apple CoreGraphics (CVE-2026-86950) - F5 BIG-IP APM (CVE-2026-94127) https://t.co/fR71dyoG2H | #CyberSafeUG #CERTUGCC https://t
@CERT_UG
29 Sept 2026
120 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
oh well, Apple addressed a zero-day vulnerability (CVE-2026-86950) that is currently being exploited in the wild interestingly, apple says: "CVE-2026-86950: Meta Product Security". does this related to a meta product support component? anyway, the flaw allows attackers to https
@UjlakiMarci
29 Sept 2026
101 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics https://
@OffensiveLab
29 Sept 2026
154 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-86950, already in the wild, forces Apple to ship an emergency patch for iOS 26 and macOS 26 this morning. Apple's emergency patch for CVE-2026-86950 fixes a vulnerability already being exploited on iOS 26 and macOS 26, while the current iOS 27 branch remains unaffected.
@0J0BIT
29 Sept 2026
188 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E820C7A6-6EBE-46FC-A3A0-E2329DED12E7",
"versionEndExcluding": "26.7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"matchCriteriaId": "FF3A9F40-6FE0-4D54-AC00-27228E5F329C",
"versionEndExcluding": "26.7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "77C881FE-1FF0-4D7A-9E5A-9E7FC6BBA3B8",
"versionEndExcluding": "15.8.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*",
"matchCriteriaId": "810BEE78-D6FB-416D-B719-A7639184DEAA",
"versionEndExcluding": "26.7.1",
"versionStartIncluding": "26.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]