CVE-2026-86950

Published Sep 28, 2026

Last updated 6 hours ago

Overview

Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Source
product-security@apple.com
NVD status
Analyzed
Products
ipados, iphone_os, macos

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Apple Multiple Products Out-of-Bounds Write Vulnerability
Exploit added on
Sep 29, 2026
Exploit action due
Oct 2, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-787

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2026-86950 — HIGH — actively exploited per CISA KEV Apple Multiple Products CVSS 8.8 | EPSS 1% #Apple #CVE https://t.co/AFzyJmqwal

    @threatpodium

    29 Sept 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Vulnerability · Exploited in the wild CVE-2026-86950 (Apple · CoreGraphics) An out‑of‑bounds write in CoreGraphics (CVE-2026-86950) can allow arbitrary code execution; Apple issued patches on Sept 28 and CISA added it to KEV with… Full report and PDF: https://t.co/zsu8q

    @gettransilience

    29 Sept 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. CVE-2026-86950 has been published. Apple Multiple Products Out-of-Bounds Write Vulnerability. Add it to your patching queue if applicable. Details: https://t.co/c5dLy169H2 #CVE #InfoSec #VulnMgmt

    @Prateektomar

    29 Sept 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🛡️ CYBER BULLETIN | 2026/09/29 🚨 1. Apple patches CoreGraphics zero-day exploited in targeted attacks CVE-2026-86950 is an out-of-bounds write in CoreGraphics that lets a crafted file trigger arbitrary code execution. Apple says it may have been used in extremely https

    @FrontieraTechIT

    29 Sept 2026

    105 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 🛡️ CYBER BULLETIN | 2026/09/29 🚨 1. Apple patches CoreGraphics zero-day exploited in targeted attacks CVE-2026-86950 is an out-of-bounds write in CoreGraphics that lets a crafted file trigger arbitrary code execution. Apple says it may have been used in extremely https

    @FrontieraTechIT

    29 Sept 2026

    157 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Patch Now | September 29, 2026 Bringing these vulnerabilities to your attention: - Citrix NetScaler: two zero-days (CVE-2026-88771, CVE-2026-88772) - Apple CoreGraphics (CVE-2026-86950) - F5 BIG-IP APM (CVE-2026-94127) https://t.co/fR71dyoG2H | #CyberSafeUG #CERTUGCC https://t

    @CERT_UG

    29 Sept 2026

    120 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. oh well, Apple addressed a zero-day vulnerability (CVE-2026-86950) that is currently being exploited in the wild interestingly, apple says: "CVE-2026-86950: Meta Product Security". does this related to a meta product support component? anyway, the flaw allows attackers to https

    @UjlakiMarci

    29 Sept 2026

    101 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics https://

    @OffensiveLab

    29 Sept 2026

    154 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2026-86950, already in the wild, forces Apple to ship an emergency patch for iOS 26 and macOS 26 this morning. Apple's emergency patch for CVE-2026-86950 fixes a vulnerability already being exploited on iOS 26 and macOS 26, while the current iOS 27 branch remains unaffected.

    @0J0BIT

    29 Sept 2026

    188 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations