Apple Warns Users iOS Vulnerability Exploited in Attack (CVE-2026-86950)
Apple patched CVE-2026-86950, an out-of-bounds write in iOS and macOS exploited in targeted attacks.
Apple released updates for CVE-2026-86950, an out-of-bounds write in iOS, iPadOS, macOS Tahoe, and macOS Sequoia that can be triggered by a maliciously crafted file and may lead to arbitrary code execution. Apple said it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific individuals on iOS versions before iOS 27. Fixed releases are iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1, with improved bounds checking. Affected devices include iPhone 11 and later and listed recent iPad models.
- CVE-2026-86950 is an out-of-bounds write that can yield arbitrary code execution.
- Apple says it was used in a sophisticated attack on specific people before iOS 27.
- Patches: iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.
- Qualys QIDs 388845, 388846, and 610810 detect vulnerable assets.
Vulnerabilities mentionedAll →
- CVE-2026-869508.8—Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOSpublished · Apple iOS KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86950 | Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOS An out-of-bounds write vulnerability (CWE-787) in Apple's CoreGraphics framework, scored 8.8 (high), allows arbitrary code execution when a device processes a maliciously crafted file, such as a malicious image or document that triggers the vulnerable rendering path. The flaw affects iPhones, iPads, and Macs, and exploitation requires no privileges but does require user interaction — the victim must open or preview the malicious file. Successful exploitation gives the attacker the ability to run code with high impact on confidentiality, integrity, and availability of the affected device. Apple states it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, indicating likely limited but real in-the-wild use. Fixes were shipped in iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1. |
Full article221 words · extracted from threatprotect.qualys.com · click to collapse
Apple released updates to address an actively exploited vulnerability tracked as CVE-2026-86950. The vulnerability affects iOS, iPadOS, macOS Tahoe, and Sequoia. This is an out-of-bounds write flaw that can be exploited by processing a maliciously crafted file. Successful exploitation of the vulnerability may lead to arbitrary code execution. Apple has addressed the vulnerability with improved bounds checking.
Apple mentioned in their advisory that they are aware of a report that the vulnerability may have been exploited in an extremely sophisticated attack against specific individuals on versions of iOS prior to iOS 27.
Affected Products and Versions
- iPhone 11 and later
- iPad 8th generation and later
- iPad Air 3rd generation and later
- iPad mini 5th generation and later
- macOS Tahoe Versions before 26.7.1
- macOS Sequoia Versions before 15.8.1
- iPad Pro 11-inch 1st generation and later
- iPad Pro 12.9-inch 3rd generation and later
Mitigation
Apple released the following versions to patch the vulnerability:
- macOS Tahoe 26.7.1
- macOS Sequoia 15.8.1
- iOS 26.7.1 and iPadOS 26.7.1
For more information, please visit the Apple security advisories for macOS Tahoe, Sequoia, and iOS and iPadOS.
Qualys Detection
Qualys customers can scan their devices with QIDs 388845, 388846, and 610810 to detect vulnerable assets.
Please continue to follow Qualys Threat Protection for more coverage of the latest vulnerabilities.
References
https://support.apple.com/en-us/149226
https://support.apple.com/en-us/149228
https://support.apple.com/en-us/149229
Text extracted automatically; images, tables and formatting may be missing. Original: