LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 29, 2026
CVSS 8.8 · High⚠ Actively exploited (CISA KEV)
8.8
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 2, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog on Sep 29, 2026, with a federal patch deadline of Oct 2, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

CVE-2026-86950 is an out-of-bounds write vulnerability in CoreGraphics affecting multiple Apple products, including iOS, macOS, and iPadOS. In plain terms, flawed handling of certain graphics-related data can allow a write past the bounds of an intended memory region. CISA notes that this may lead to arbitrary code execution. For IT and security teams, that means a successful attack could compromise a device’s integrity and the data and sessions it holds, so inventory, patching, and monitoring should be treated as priority work once the vendor advisory is reviewed.

Public detail in the record is limited to the CoreGraphics component and the out-of-bounds write class (CWE-787). Exact affected build numbers, attack vectors, and scoring must be confirmed against Apple’s advisory and your own asset data. Known ransomware use is not documented for this CVE.

How it works

CWE-787 (out-of-bounds write) occurs when software writes data outside the memory buffer or object it was meant to use. In a graphics stack such as CoreGraphics, that often involves parsing or rendering image, path, font, or similar content. If bounds checks fail, attacker-controlled or malformed input can corrupt adjacent memory.

At a high level, an attacker who can get the vulnerable code path to process untrusted content may influence what is written and where. Depending on process privileges, memory layout, and mitigations already present on the platform, that corruption can escalate to arbitrary code execution in the affected process or further compromise. Do not assume a specific delivery method (for example local file, web content, or inter-process data) without reading the vendor advisory; mechanics and preconditions vary by release and configuration.

Defenders should treat this as a memory-safety defect in a widely used system framework: any workflow that feeds external or semi-trusted graphical data into CoreGraphics is in scope until patched builds are confirmed.

Am I affected? How to find it in your systems

Apple iOS, macOS, and iPadOS are named in the CISA summary as containing the CoreGraphics flaw. These systems typically appear as employee and executive phones and tablets, Mac endpoints (including those used for development and creative work), shared kiosks, and managed devices in MDM or Apple Business Manager inventories. CoreGraphics is a system framework, so exposure is generally tied to OS version rather than a separately installed app.

Telemetry signs of exploitation are not detailed in the provided facts. In general, for this weakness class, watch for unexpected process crashes in graphics-related components, abnormal code-signing or integrity alerts, sudden privilege or persistence changes, and EDR detections tied to memory corruption or suspicious child processes after opening images or documents. Confirm any IOCs or log guidance against the vendor advisory and your EDR vendor’s content. Forensic triage should follow your standard process and any applicable CISA forensics guidance referenced for federal or aligned stakeholders.

How to remediate

Patch first. Apply the Apple updates that address CVE-2026-86950 on every affected iOS, macOS, and iPadOS system, following the vendor’s instructions. CISA’s required action is to apply mitigations per vendor instructions, ensure compliance with BOD 26-04 prioritization of security updates based on risk, and follow CISA’s forensics triage requirements where they apply. For cloud-associated or managed service contexts, follow applicable BOD 26-04 guidance; if mitigations are unavailable, discontinue use of the product as directed by that guidance. Stakeholders must evaluate each asset’s internet exposure and meet BOD 26-04 patching expectations.

Hardening for this class includes reducing untrusted content reach (mail and browser isolation where used), keeping platform exploit mitigations and SIP/system integrity features enabled, and limiting local admin and sideload paths so post-exploitation is harder.

If you can't patch immediately

Compensating controls reduce—but do not eliminate—risk until vendor fixes are installed.

If mitigations truly cannot be applied, plan to discontinue use of affected products for sensitive work until a fixed build is deployed, consistent with the CISA action language.

If your data may have been exposed

Actively exploited vulnerabilities can lead to device compromise and follow-on data theft, even when ransomware use is not documented for this CVE. If you suspect exposure, isolate affected devices, preserve logs and images for triage, rotate credentials accessible from those devices, and complete incident procedures aligned with your policy and any required federal triage guidance. As a simple personal check, individuals can run a free exposure scan of their email addresses against known breach datasets to see whether their accounts already appear in public breach collections and then prioritize password and MFA hygiene accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedApple · Multiple Products
WeaknessCWE-787
CVSS base score8.8 (High)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
PublishedSep 28, 2026
Added to CISA KEVSep 29, 2026
Federal patch deadlineOct 2, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities