Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-29 · updated: 2026-09-29 · tags: [cve, apple, macos, ios, endpoint-security, memory-corruption] · confidence: high · severity: high · affected_sectors: [global] · au_impact: false

An out-of-bounds write (CWE-787) in Apple's CoreGraphics component, addressed with improved bounds checking. Processing a maliciously crafted file may lead to arbitrary code execution. Apple credits Meta Product Security with discovering and reporting the issue.

Attribute Detail
CVE CVE-2026-86950
CVSS 8.8 (High, CVSS v3.1)
Vendor / product Apple — CoreGraphics (iOS, iPadOS, macOS)
Reported 2026-09-28

Affected and fixed versions

Platform Fixed in
iOS / iPadOS 26.7.1
macOS Tahoe 26.7.1
macOS Sequoia 15.8.1

The update covers iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.

Exploitation status

Apple states it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. It did not state how many individuals were targeted, whether any attempts succeeded, or when exploitation began.

Source