Apple Emergency Patch for iOS 26/macOS26/macOS15 (CVE-2026-86950), (Mon, Sep 28th)
Apple patched exploited CVE-2026-86950 in iOS 26, macOS 26, and macOS 15 after targeted attacks.
Apple released updates across its operating systems, but only older branches include a security fix for CVE-2026-86950. The flaw affects iOS 26, macOS 26, and macOS 15 and is already being exploited; iOS 27 and macOS 27 are not affected. Apple, crediting Meta Product Security, said the issue may have been used in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 27. The current 27-branch update addresses functional issues only.
- CVE-2026-86950 is already exploited against specific targeted people.
- Fixes apply to iOS 26, macOS 26, and macOS 15 only.
- iOS 27 and macOS 27 are not affected by the flaw.
- Meta Product Security reported the issue to Apple.
Vulnerabilities mentionedAll →
- CVE-2026-869508.8—Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOSpublished · Apple iOS KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86950 | Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOS An out-of-bounds write vulnerability (CWE-787) in Apple's CoreGraphics framework, scored 8.8 (high), allows arbitrary code execution when a device processes a maliciously crafted file, such as a malicious image or document that triggers the vulnerable rendering path. The flaw affects iPhones, iPads, and Macs, and exploitation requires no privileges but does require user interaction — the victim must open or preview the malicious file. Successful exploitation gives the attacker the ability to run code with high impact on confidentiality, integrity, and availability of the affected device. Apple states it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, indicating likely limited but real in-the-wild use. Fixes were shipped in iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1. |
Full article161 words · extracted from isc.sans.edu · click to collapse
Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today's update for the current "27" branch does not address security issues, but fixes some functional issues that got caught after the release two weeks ago. A 27.1 version was also expected to support the new foldable iPhone and will likely include specific features geared to the soon to be available device.
Apple credits Meta Product Security with reporting the vulnerability and states that: "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27".
--
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|
Text extracted automatically; images, tables and formatting may be missing. Original: https://isc.sans.edu/diary/rss/33376