Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOS
CISA: Apple Multiple Products Out-of-Bounds Write Vulnerability
CVSS 3.1
8.8high
EPSS
—
Published
()
KEV added
AI analysis
An out-of-bounds write vulnerability (CWE-787) in Apple's CoreGraphics framework, scored 8.8 (high), allows arbitrary code execution when a device processes a maliciously crafted file, such as a malicious image or document that triggers the vulnerable rendering path. The flaw affects iPhones, iPads, and Macs, and exploitation requires no privileges but does require user interaction — the victim must open or preview the malicious file. Successful exploitation gives the attacker the ability to run code with high impact on confidentiality, integrity, and availability of the affected device. Apple states it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, indicating likely limited but real in-the-wild use. Fixes were shipped in iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1.
What to do: Patch immediately to iOS 26.7.1 / iPadOS 26.7.1 on mobile and macOS Sequoia 15.8.1 or macOS Tahoe 26.7.1 on Macs; push these updates via MDM and verify fleet-wide compliance. Because the attack requires the victim to process a maliciously crafted file, advise users — especially journalists, activists, executives, and other likely targets of sophisticated attacks — not to open unsolicited attachments or media files from unknown senders. Review device logs and EDR telemetry for anomalous process activity following the opening of unexpected files on unpatched devices.
Affected
Apple iOS
versions before iOS 26.7.1
Apple iPadOS
versions before iPadOS 26.7.1
Apple macOS Sequoia
versions before 15.8.1
Apple macOS Tahoe
versions before 26.7.1
Estimated exposure
mass
Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
CISA Known Exploited Vulnerability
Affected
Apple Multiple Products
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
≈ hundreds of millions to over a billion devices (order of 1e9) — All unpatched iPhones, iPads, and Macs worldwide are vulnerable, and Apple's publicly reported active device base is over 2 billion units, so the susceptible population plausibly sits in the hundreds of millions even after typical patch…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Apple patched CVE-2026-86950, an out-of-bounds write in iOS and macOS exploited in targeted attacks.
Apple released updates for CVE-2026-86950, an out-of-bounds write in iOS, iPadOS, macOS Tahoe, and macOS Sequoia that can be triggered by a maliciously crafted file and may lead to arbitrary code execution. Apple said it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific individuals on iOS versions before iOS 27. Fixed releases are iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1, with improved bounds checking. Affected devices include iPhone 11 and later and listed recent iPad models.
Apple fixed actively exploited Core Graphics zero-day CVE-2026-86950 that enables code execution from a malicious file.
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 to fix CVE-2026-86950, an out-of-bounds write in Core Graphics. Processing a maliciously crafted file can lead to arbitrary code execution. Apple said the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 27. Meta Product Security reported the flaw, and Apple’s iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 updates do not list the CVE.
Apple patched CVE-2026-86950, a CoreGraphics flaw possibly exploited in targeted iPhone attacks via malicious files.
Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics that can let an attacker run code when a device processes a maliciously crafted file. Apple says it is aware of a report that the flaw may have been exploited in an extremely sophisticated, highly targeted attack against specific iPhone users on iOS versions before iOS 27. Fixes are in iOS and iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1, addressed with improved bounds checking.
Apple patched exploited CVE-2026-86950 in iOS 26, macOS 26, and macOS 15 after targeted attacks.
Apple released updates across its operating systems, but only older branches include a security fix for CVE-2026-86950. The flaw affects iOS 26, macOS 26, and macOS 15 and is already being exploited; iOS 27 and macOS 27 are not affected. Apple, crediting Meta Product Security, said the issue may have been used in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 27. The current 27-branch update addresses functional issues only.
Apple patched actively exploited CoreGraphics zero-day CVE-2026-86950 enabling arbitrary code execution via crafted files in targeted attacks on iOS users.
Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026, fixing CVE-2026-86950, an out-of-bounds write in CoreGraphics that allows arbitrary code execution when a device processes a maliciously crafted file. Apple states the flaw may have been exploited in an extremely sophisticated attack against specifically targeted individuals on iOS versions before iOS 27, a pattern consistent with spyware operations. The vulnerability affects iPhone 11 and later plus supported iPad Pro, iPad Air, iPad, and iPad mini models, and was reported by Meta Product Security.
Apple patched CoreGraphics CVE-2026-86950, which may have been exploited in targeted iOS attacks.
Apple released updates for an out-of-bounds write in CoreGraphics, CVE-2026-86950, that can allow arbitrary code execution when processing a malicious file. The company said it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific people on iOS versions before iOS 27. Fixes are in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1; Meta Product Security reported the bug. Apple previously patched a separate dyld issue, CVE-2026-20700, that it said was used in sophisticated attacks.
Apple patched actively exploited CoreGraphics zero-day CVE-2026-86950 in iOS/iPadOS 26.7.1, used in sophisticated attacks on targeted individuals.
CVE-2026-86950 is an out-of-bounds write in CoreGraphics where processing a maliciously crafted file can allow arbitrary code execution; Apple fixed it with improved bounds checking in iOS 26.7.1 and iPadOS 26.7.1. Apple stated the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 27, suggesting possible spyware use. Meta Product Security reported the flaw, and it is the seventh zero-day Apple has fixed this year. Affected devices include iPhone 11 and later, iPad Pro, iPad Air, iPad (8th gen+), and iPad mini (5th gen+).
Apple patched CoreGraphics zero-day CVE-2026-86950 (out-of-bounds write enabling arbitrary code execution) reportedly exploited in sophisticated targeted attacks on iOS users.
CVE-2026-86950 is an out-of-bounds write in Apple CoreGraphics that enables arbitrary code execution when the system processes a maliciously crafted file; Apple says it may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before 27. The flaw affects iOS and iPadOS 26.7 and earlier plus supported macOS Tahoe and Sequoia, and was fixed in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Meta Product Security discovered and reported the vulnerability, but Apple has not disclosed targets, threat actors, or the delivery method. CISA had not yet added the CVE to its Known Exploited Vulnerabilities catalog, and the article notes prior Apple zero-days CVE-2026-20700, CVE-2025-43300 and CVE-2025-55177 exploited in sophisticated attacks.
Apple patched graphics-engine CVE-2026-86950 in iOS 26 after possible targeted exploitation.
Apple patched CVE-2026-86950 in iOS 26, iPadOS 26, and macOS 26 after saying it may have been exploited in extremely sophisticated attacks against specific people. The flaw is in the graphics engine that draws the interface; a successful exploit could expose a broad range of personal data. Apple says roughly four in five iPhones still run iOS 26, while iOS 27, iPadOS 27, and macOS 27 are unaffected. A separate zero-click bug, CVE-2026-86869, fixed with those 27 releases, could be triggered by a malicious iMessage and bypass BlastDoor; use before the fix is not confirmed.
Apple patched actively exploited CoreGraphics zero-day CVE-2026-86950 in iOS/iPadOS 26.7.1, enabling arbitrary code execution via crafted files in targeted attacks.
Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026 to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics that allows arbitrary code execution when a device processes a maliciously crafted file. Apple acknowledged reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 27. Meta Product Security reported the vulnerability, and the fix implements improved bounds checking. Updates cover iPhone 11 and later plus most recent iPads.
Apple's iOS and macOS updates fix CoreGraphics zero-day CVE-2026-86950, reported by Meta and possibly exploited in targeted attacks on iOS users.
Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics enabling arbitrary code execution via specially crafted files, in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Apple says the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, and was reported by Meta's product security team. Because CoreGraphics handles 2D graphics and PDF rendering system-wide, delivery could occur via web pages, email attachments, or messaging previews, potentially enabling zero-click exploitation; CISA has not yet added the CVE to its KEV catalog.
Apple says CVE-2026-86950 may have been exploited across its OS lineup, and CISA added it to KEV.
Canada's Cyber Centre advisory AV26-971 says Apple products including iOS, iPadOS, macOS Golden Gate, Tahoe and Sequoia, watchOS, and visionOS 27 are affected before specified point releases. Apple indicated CVE-2026-86950 may have been exploited. On September 29, 2026, CISA added the CVE to the Known Exploited Vulnerabilities catalog. Administrators are urged to review Apple's security releases and install updates.
CISA added actively exploited Apple out-of-bounds write CVE-2026-86950 to the KEV catalog.
CISA added CVE-2026-86950, an out-of-bounds write affecting multiple Apple products, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk KEV entries on publicly exposed assets and to check whether systems were compromised before patching. CISA says this vulnerability class is a frequent attack vector and encourages all organizations to remediate KEV flaws using risk-based vulnerability management.