An out-of-bounds write (CWE-787) in Apple's CoreGraphics component, addressed with improved bounds checking. Processing a maliciously crafted file may lead to arbitrary code execution. Apple credits Meta Product Security with discovering and reporting the issue.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-86950 |
| CVSS | 8.8 (High, CVSS v3.1) |
| Vendor / product | Apple — CoreGraphics (iOS, iPadOS, macOS) |
| Reported | 2026-09-28 |
Affected and fixed versions
| Platform | Fixed in |
|---|---|
| iOS / iPadOS | 26.7.1 |
| macOS Tahoe | 26.7.1 |
| macOS Sequoia | 15.8.1 |
The update covers iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
Exploitation status
Apple states it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. It did not state how many individuals were targeted, whether any attempts succeeded, or when exploitation began.