Apple security advisory (AV26-971)
Apple says CVE-2026-86950 may have been exploited across its OS lineup, and CISA added it to KEV.
Canada's Cyber Centre advisory AV26-971 says Apple products including iOS, iPadOS, macOS Golden Gate, Tahoe and Sequoia, watchOS, and visionOS 27 are affected before specified point releases. Apple indicated CVE-2026-86950 may have been exploited. On September 29, 2026, CISA added the CVE to the Known Exploited Vulnerabilities catalog. Administrators are urged to review Apple's security releases and install updates.
- CVE-2026-86950 affects iOS, iPadOS, macOS, watchOS, and visionOS before the listed updates.
- Apple indicated the flaw may already have been exploited.
- CISA added CVE-2026-86950 to the KEV catalog on September 29, 2026.
- The Cyber Centre urges users and administrators to apply available Apple updates.
Vulnerabilities mentionedAll →
- CVE-2026-869508.8—Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOSpublished · Apple iOS KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86950 | Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOS An out-of-bounds write vulnerability (CWE-787) in Apple's CoreGraphics framework, scored 8.8 (high), allows arbitrary code execution when a device processes a maliciously crafted file, such as a malicious image or document that triggers the vulnerable rendering path. The flaw affects iPhones, iPads, and Macs, and exploitation requires no privileges but does require user interaction — the victim must open or preview the malicious file. Successful exploitation gives the attacker the ability to run code with high impact on confidentiality, integrity, and availability of the affected device. Apple states it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, indicating likely limited but real in-the-wild use. Fixes were shipped in iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1. |
Full article115 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-971
Date: September 29, 2026
As of September 28, 2026, Apple is affected by a vulnerability in the following products:
- iOS and iPadOS
- Prior to 27.0.1
- Prior to 26.7.1
- macOS Golden Gate
- Prior to 27.0.1
- macOS Tahoe
- Prior to 26.7.1
- macOS Sequoia
- Prior to 15.8.1
- watchOS
- Prior to 27.0.1
- visionOS 27
- Prior to 27.0.1
Apple has indicated that CVE-2026-86950 may have been exploited.
On September 29, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86950 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-971