CVE-2026-86950
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
- Published Sep 28, 2026
- CVSS 8.8 high
- 1.2% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A fix is available
Affected software
In the news
- Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path The Hacker News ·
- A Vulnerability in Apple Products Could Allow for Arbitrary Code Execution CIS MS-ISAC ·
- Apple Zero-Day Vulnerability Weaponized in Targeted Attacks Dark Reading ·
- Apple security advisory (AV26-971) Canadian Centre for Cyber Security ·
- CISA Adds One Known Exploited Vulnerability to Catalog CISA ·
- Update your iPhone, iPad, or Mac: Flaw could run attackers’ code Malwarebytes Labs ·
- Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950) Help Net Security ·
- Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ SecurityWeek ·
- Vulnerability in Apple products CERT-FR ·
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks The Hacker News ·