CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
CVE-2026-86950 is an out-of-bounds write vulnerability in CoreGraphics affecting multiple Apple products, including iOS, macOS, and iPadOS. In plain terms, flawed handling of certain graphics-related data can allow a write past the bounds of an intended memory region. CISA notes that this may lead to arbitrary code execution. For IT and security teams, that means a successful attack could compromise a device’s integrity and the data and sessions it holds, so inventory, patching, and monitoring should be treated as priority work once the vendor advisory is reviewed.
Public detail in the record is limited to the CoreGraphics component and the out-of-bounds write class (CWE-787). Exact affected build numbers, attack vectors, and scoring must be confirmed against Apple’s advisory and your own asset data. Known ransomware use is not documented for this CVE.
How it works
CWE-787 (out-of-bounds write) occurs when software writes data outside the memory buffer or object it was meant to use. In a graphics stack such as CoreGraphics, that often involves parsing or rendering image, path, font, or similar content. If bounds checks fail, attacker-controlled or malformed input can corrupt adjacent memory.
At a high level, an attacker who can get the vulnerable code path to process untrusted content may influence what is written and where. Depending on process privileges, memory layout, and mitigations already present on the platform, that corruption can escalate to arbitrary code execution in the affected process or further compromise. Do not assume a specific delivery method (for example local file, web content, or inter-process data) without reading the vendor advisory; mechanics and preconditions vary by release and configuration.
Defenders should treat this as a memory-safety defect in a widely used system framework: any workflow that feeds external or semi-trusted graphical data into CoreGraphics is in scope until patched builds are confirmed.
Am I affected? How to find it in your systems
Apple iOS, macOS, and iPadOS are named in the CISA summary as containing the CoreGraphics flaw. These systems typically appear as employee and executive phones and tablets, Mac endpoints (including those used for development and creative work), shared kiosks, and managed devices in MDM or Apple Business Manager inventories. CoreGraphics is a system framework, so exposure is generally tied to OS version rather than a separately installed app.
- Inventory all Apple endpoints via MDM, endpoint management, configuration management databases, and network/device discovery; record OS family and full version/build.
- Compare each build to the fixed versions listed in Apple’s security advisory for CVE-2026-86950; do not rely on marketing version names alone.
- Flag internet-exposed or high-risk roles first (remote access, VIP, developers handling untrusted media, devices that open email or web content broadly).
- Review whether unmanaged or BYOD Apple devices access corporate mail, VPN, or SaaS; include them in scope for policy even if patching is user-driven.
Telemetry signs of exploitation are not detailed in the provided facts. In general, for this weakness class, watch for unexpected process crashes in graphics-related components, abnormal code-signing or integrity alerts, sudden privilege or persistence changes, and EDR detections tied to memory corruption or suspicious child processes after opening images or documents. Confirm any IOCs or log guidance against the vendor advisory and your EDR vendor’s content. Forensic triage should follow your standard process and any applicable CISA forensics guidance referenced for federal or aligned stakeholders.
How to remediate
Patch first. Apply the Apple updates that address CVE-2026-86950 on every affected iOS, macOS, and iPadOS system, following the vendor’s instructions. CISA’s required action is to apply mitigations per vendor instructions, ensure compliance with BOD 26-04 prioritization of security updates based on risk, and follow CISA’s forensics triage requirements where they apply. For cloud-associated or managed service contexts, follow applicable BOD 26-04 guidance; if mitigations are unavailable, discontinue use of the product as directed by that guidance. Stakeholders must evaluate each asset’s internet exposure and meet BOD 26-04 patching expectations.
- Stage updates in MDM rings: pilot, broad production, then stragglers; verify build numbers post-install.
- Enforce minimum OS versions in compliance policies; block or quarantine non-compliant devices from sensitive resources.
- After patching, re-enable any temporary hardening only if still needed for defense in depth.
- Document exception risk acceptance with owners and expiry dates tied to patch availability.
Hardening for this class includes reducing untrusted content reach (mail and browser isolation where used), keeping platform exploit mitigations and SIP/system integrity features enabled, and limiting local admin and sideload paths so post-exploitation is harder.
If you can't patch immediately
Compensating controls reduce—but do not eliminate—risk until vendor fixes are installed.
- Segmentation and access: Isolate unpatched devices from crown-jewel networks; require stronger authentication and conditional access; prefer managed browsers or remote app delivery for high-risk browsing.
- Feature and content controls: Where policy allows, restrict automatic opening of complex attachments and untrusted media; use enterprise content filters; disable unnecessary preview or auto-render paths if Apple or your MDM documents a safe option—confirm any setting against vendor guidance so you do not break security features.
- Virtual patching / filtering: Network or email gateways that block known-malicious file patterns may help for commodity delivery; they are not a substitute for an OS fix for a framework-level write bug.
- Monitoring: Heighten EDR sensitivity on unpatched cohorts; alert on crashes, memory-corruption related detections, new persistence, and anomalous outbound connections; capture volatile evidence per your IR plan if compromise is suspected.
- Exposure reduction: Remove public or broad network exposure of management services on Macs; shorten DHCP/lease and certificate lifetimes for non-compliant devices.
If mitigations truly cannot be applied, plan to discontinue use of affected products for sensitive work until a fixed build is deployed, consistent with the CISA action language.
If your data may have been exposed
Actively exploited vulnerabilities can lead to device compromise and follow-on data theft, even when ransomware use is not documented for this CVE. If you suspect exposure, isolate affected devices, preserve logs and images for triage, rotate credentials accessible from those devices, and complete incident procedures aligned with your policy and any required federal triage guidance. As a simple personal check, individuals can run a free exposure scan of their email addresses against known breach datasets to see whether their accounts already appear in public breach collections and then prioritize password and MFA hygiene accordingly.
AICompiled with AI assistance from public sources and published under our editorial standards.
Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H