U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog
CISA adds exploited Apple CoreGraphics zero-day CVE-2026-86950 to the Known Exploited Vulnerabilities catalog.
CISA added Apple CoreGraphics flaw CVE-2026-86950, an out-of-bounds write scored CVSS 8.8, to the Known Exploited Vulnerabilities catalog. Apple said processing a maliciously crafted file can lead to arbitrary code execution and that the issue may have been exploited in an extremely sophisticated attack against specific people on iOS versions before iOS 27. Fixes are in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Meta Product Security reported the bug, and CISA ordered federal agencies to patch by October 2, 2026. Apple has not confirmed how the malicious files were delivered.
- CVE-2026-86950 is an out-of-bounds write in CoreGraphics, CVSS 8.8.
- Apple says it may have been exploited against specific targeted individuals.
- Patches are in iOS 26.7.1, iPadOS 26.7.1, and two macOS releases.
- Meta Product Security discovered and reported the vulnerability.
- Federal agencies must remediate by October 2, 2026.
Vulnerabilities mentionedAll →
- CVE-2026-869508.8<1%Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOSpublished · Apple iOS KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86950 |
Full article496 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 30, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog.
This week, Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability CVE-2026-86950 in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when the system processes a specially crafted file.
The vulnerability affects iOS 26.7 and earlier versions before iOS 27, as well as iPadOS 26.7 and earlier and supported versions of macOS Tahoe and macOS Sequoia. Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the issue.
“Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” reads Apple’s advisory. “Description: “An out-of-bounds write issue was addressed with improved bounds checking.”
Apple says it knows of a report that the flaw may have been exploited in an “extremely sophisticated attack against specific targeted individuals” running versions of iOS before iOS 27.
Apple hasn’t disclosed who was targeted, how many people were affected, whether the attacks succeeded, or when exploitation started. It also hasn’t explained how attackers delivered the malicious files. That leaves an important part of the attack chain unknown.
CoreGraphics handles graphics and rendering functions across Apple’s operating systems, including processing content such as images and PDFs. Attackers can trigger the flaw by tricking the victim into opening a malicious file sent through a web page, an email attachment, or a messaging application, However, Apple hasn’t confirmed any of these delivery methods for CVE-2026-86950.
That distinction matters. A crafted file doesn’t need to look like an obvious executable for a vulnerability in a system component that processes content to become useful to an attacker. The security boundary can be crossed while the operating system is simply doing what it’s designed to do: interpreting a file.
Meta Product Security discovered and reported the vulnerability to Apple. The involvement of Meta is particularly interesting because the company has previously identified attacks involving Apple vulnerabilities and targeted users of its messaging platforms.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the flaw by October 2nd, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)