CVE-2026-86869(apple / ipados)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27. Processing a maliciously crafted image may lead to unexpected app termination.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ipadosiphone_osmacos

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-26: 109-26
Referenced assets1 URL
By indicator
Full discourse1 post
  • Mr.Niko@_MrNiko

    iMessage EXR. zero click. heap overflow before the banner finishes. CVE-2026-86869. libAppleEXR sizes the buffer for 3 channels. 12 bytes. CompressedInterleave4 writes 4. 16 bytes. every pixel. three of those four bytes come from the file. BlastDoor never decodes EXR. Spotlight and the photo indexer do, later, with SDR hardcoded on. no tap. same ImageIO path on iPhone, iPad, and Mac. fixed in the 27 releases. older fleet still sits on it. credit: Niels Hofmans / ironPeak https://ironpeak.be/blog/ex-arrr-sailing-the-0-click-seas/ #iOS #ExploitDev #InfoSec

    723215010213.0K
    1.4K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---

Explore more