CVE-2026-86950(apple / ipados)

LOWCVSS 8.8 · HIGHCISA KEV

Signal is active with 45 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-10-02. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ipados
  • iphone_os
  • macos

Threat summary

  • 64 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 45 mentions on most recent observed day (2026-09-29)
  • 64 total mentions across 2 days

Affected systems

Vendors
Products
ipadosiphone_osmacos

Deep dive

Activity timeline64 mentions / 2d
011233445Mentions · 2026-09-28: 19Mentions · 2026-09-29: 4509-2809-29
Referenced assets39 URLs
By indicator
Full discourse20 posts
  • The Hacker News@TheHackersNews

    ‼️ Apple patched a new CoreGraphics flaw that may have been exploited in targeted iOS attacks. CVE-2026-86950 can trigger arbitrary code execution when a maliciously crafted file is processed. Fixes are available for affected older iOS, iPadOS, and macOS releases. Read: https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html

    44351433040.4K
    2.4M followersView on X
  • Mateusz Krzywicki@krzywix

    Apple iOS in-the-wild - CVE-2026-86950 in CoreGraphics reported by Meta Product Security https://support.apple.com/en-us/149226

    081933711.8K
    2.1K followersView on X
  • SlowMist@SlowMist_Team

    🚨 Apple has released an important security update for iOS/iPadOS 26.7.1, addressing CVE-2026-86950, an out-of-bounds write vulnerability that may lead to arbitrary code execution. As we previously reported, this update is highly relevant to the iOS attack activity we have been tracking. Apple confirmed that the vulnerability may have been exploited in highly sophisticated attacks targeting specific individuals on iOS versions before iOS 27. For crypto users, this is especially concerning given the iOS exploitation activity we have observed targeting sensitive wallet data. 🔐 Please: • Update your iPhone, iPad, Mac and other Apple devices to the latest available security updates. • Avoid installing apps from unknown or untrusted sources. • Do not open suspicious links in Safari or in-app browsers. • Treat unexpected files, links and app installation prompts with caution. Stay alert and keep your devices updated. Apple Security Update: https://support.apple.com/en-us/149226

    211730911.9K
    90.6K followersView on X
  • ApplSec@ApplSec

    📣 EMERGENCY UPDATE 📣 Apple pushed updates for a new zero-day that may have been actively exploited. 🐛 CVE-2026-86950 (CoreGraphics): - iOS and iPadOS 26.7.1 - macOS Sequoia 15.8.1 - macOS Tahoe 26.7.1

    03024104.0K
    1.4K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🍎 🚨 APPLE PATCHES COREGRAPHICS FLAW THAT MAY HAVE BEEN EXPLOITED IN TARGETED ATTACKS Apple has released security updates for older iOS, iPadOS, and macOS versions addressing CVE-2026-86950, an out-of-bounds write in CoreGraphics that can lead to arbitrary code execution when processing a maliciously crafted file. Key points from Apple: • Impact: processing a crafted file may lead to arbitrary code execution • Fix: improved bounds checking • Credited: Meta Product Security • Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27 • No public detail yet on volume of targets, success, or first exploitation date Patched in: • iOS 26.7.1 and iPadOS 26.7.1 • macOS Tahoe 26.7.1 • macOS Sequoia 15.8.1 ⚠️ Analyst Note: Apple’s wording indicates possible targeted exploitation on pre–iOS 27 builds, not confirmed mass exploitation. Treat this as a high-priority patch advisory: update eligible devices promptly, and do not overstate the attack as a broad consumer campaign without further evidence. Sources (Apple Support): https://support.apple.com/en-us/149226 https://support.apple.com/en-us/149228 https://support.apple.com/en-us/149229 #Apple #iOS #macOS #CVE #CoreGraphics #ZeroDay #ThreatIntel #CyberSecurity #DDW

    0401635.2K
    205.2K followersView on X
  • Decipher@DecipherSec

    New Apple updates are out to patch an actively exploited bug in iOS and macOS. CVE-2026-86950. https://support.apple.com/en-us/149226

    06032813
    4.4K followersView on X
  • 蓝点网@landiantech

    苹果发布 iOS 26.7.1 版修复图形组件高危漏洞,该漏洞已经被黑客用于展开攻击,但是否与近期币圈发生的攻击有关还无法确认。 CVE-2026-86950 位于 CoreGraphics 组件中,涉及图像、界面和其他视觉内容渲染。 近期有恶意应用针对币圈用户发起攻击,因此有人将该漏洞与币圈攻击联系起来,不过从已知情况来看币圈发生的攻击主要应该还是 DarkSword 攻击链,可能与最新修复的漏洞无关。 查看全文:https://ourl.co/127100?x

    000822.3K
    38.3K followersView on X
  • SANS.edu Internet Storm Center@sans_isc

    Apple Emergency Patch for iOS 26/macOS26/macOS15 (CVE-2026-86950) https://isc.sans.edu/diary/33376 https://t.co/sa1azqUyyT

    030522.5K
    118.3K followersView on X
  • Dylan X@dylanyu88

    🚨 苹果紧急修复 iOS 高危漏洞,或已被用于定向攻击 苹果发布 iOS/iPadOS 26.7.1 安全更新,修复 CoreGraphics 越界写入漏洞 CVE-2026-86950。 该漏洞在处理恶意构造文件时,可能导致任意代码执行。更值得注意的是,苹果表示,该漏洞可能已被用于针对特定个人的高度复杂攻击,涉及 iOS 27 之前的版本。 目前苹果没有公布受影响的具体目标或攻击规模。 如果你的设备仍运行 iOS 26,建议尽快更新至 iOS 26.7.1。iPad 和符合条件的 Mac 也应安装对应安全更新。 ⚠️ 同时避免打开来源不明的文件或可疑链接。

    40050290
    5.5K followersView on X
  • Bitcoin Addict Thailand@BitcoinAddictTH

    Apple ปล่อยแพตช์ฉุกเฉิน iOS 26.7.1 ปิดช่องโหว่ Zero-Day CVE-2026-86950 คนพบไม่ใช่ Apple เอง แต่เป็นทีม Meta Product Security . SlowMist เตือนน่าจะเป็นช่องโหว่ที่ถูกใช้ดูดกระเป๋าคริปโตจริง แต่ประกาศทางการของ Apple ไม่ได้พูดถึงคริปโตเลยสักคำ . เป็นการประเมินของ SlowMist ฝ่ายเดียว ย https://t.co/Rn0zvyrC7V

    11061628
    57.0K followersView on X
  • AplWire@AplWire

    iOS 26.7.1 and iPadOS 26.7.1 fixes - CVE-2026-86950: Meta Product Security Impact: Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. Description: An out-of-bounds write issue was addressed with improved bounds checking.

    00030150
    42 followersView on X
  • Help Net Security@helpnetsecurity

    Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950) - https://www.helpnetsecurity.com/2026/09/29/apple-core-graphics-zero-day-cve-2026-86950-fixed/ - @Apple #0day #iOS #iPad #macOS #Cybersecurity #CybersecurityNews https://t.co/p3xyNmJ6q5

    00011236
    60.2K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews

    Apple patched CVE-2026-86950, a CoreGraphics zero-day on iOS and macOS that may have enabled code execution in highly targeted attacks. Meta's security team reported the issue. #Apple #CoreGraphics #Meta https://www.hendryadrian.com/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack/

    01010172
    4.8K followersView on X
  • Eduard Kovacs@EduardKovacs

    Apple patched a CoreGraphics zero-day (CVE-2026-86950) reported by Meta, warning the flaw was targeted in extremely sophisticated attacks. https://www.securityweek.com/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack/

    00011177
    13.8K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Learn about the critical CVE-2026-86950 zero-day vulnerability patched in iOS 26.7.1. Discover how this CoreGraphics flaw could lead to malicious code execution. #AppleSecurity #iOSUpdate #ZeroDay #CyberSecurity #TechNews https://securityexpress.info/apple-patches-zero-day-ios-26-7-1/

    00020441
    13.0K followersView on X
  • ExploitGrid@exploitgrid

    🚨 Apple patched CVE-2026-86950, a CoreGraphics flaw that can lead to arbitrary code execution through a maliciously crafted file. Apple says it may have been exploited in a highly targeted attack. No public exploit known. 🔎 https://exploitgrid.net/vulnerabilities/CVE-2026-86950

    00011208
    193 followersView on X
  • Diario฿itcoin@DiarioBitcoin

    🚨 Apple corrige una falla de seguridad en iPhone iOS 26.7.1 y iPadOS 26.7.1 parchean CVE-2026-86950, que podía permitir ejecutar código tras procesar un archivo manipulado. Apple reportó posible explotación en ataques dirigidos. SlowMist alerta a usuarios cripto, pero no confirmó que la falla causara robos de billeteras. Actualiza tu dispositivo.

    10000256
    213.2K followersView on X
  • National CERT/CC@CERT_UG

    Patch Now | September 29, 2026 Bringing these vulnerabilities to your attention: - Citrix NetScaler: two zero-days (CVE-2026-88771, CVE-2026-88772) - Apple CoreGraphics (CVE-2026-86950) - F5 BIG-IP APM (CVE-2026-94127) https://cert.ug | #CyberSafeUG #CERTUGCC https://t.co/KmgcRDvkDe

    1000036
    1.5K followersView on X
  • Keystone 中文@KeystoneCN

    Apple 发布了 iOS / iPadOS 26.7.1,主要修复 CVE-2026-86950。 该漏洞可能通过恶意文件触发任意代码执行,Apple 表示它可能已经被用于针对特定目标的高级攻击。 结合近期针对 iOS 加密货币用户的攻击事件,如果还在使用旧版 iOS,建议尽快升级。 手机系统即使采用了沙盒隔离设计,也存在利用漏洞实现逃逸的可能,并非绝对安全。 对于加密资产,除了及时更新系统,也尽量不要把助记词和私钥留在手机里,使用硬件钱包将私钥与联网设备隔离。🔐

    00010585
    9.1K followersView on X
  • 0xvi@0xvitech

    Other side. Targeted + “extremely sophisticated” is how Apple usually talks when the buyer is a spy shop and the set is small. Most people on iOS 26 are not that set. Once the CVE is public, opportunistic copycats become a separate problem. Unpatched 26.x / Tahoe / Sequoia is the exposed set now, even if you were never in the original targeting. CISA KEV, checked this morning: CVE-2026-86950 is not in the adds I can see. NetScaler 88771/88772 from 27 Sep are. Absence of KEV is not absence of risk. It is absence of CISA’s listing. Also: at least one writeup mixed this bug with CVE-2026-20700, a February dyld memory-corruption issue. Different component, different month. Flattening CVE numbers is how bad threads get born.

    1000060
    193 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSappleipados---
OSappleiphone_os---
OSapplemacos---

Explore more