Apple Multiple Products Out-of-Bounds Write Vulnerability
TL;DR 📌
- Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
- Highest CVSS: 8.8 (High).
- Listed in CISA KEV (2026-09-29) — this is being exploited in the wild.
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2026-86950.
What it is
CVE-2026-86950 is an out-of-bounds write in CoreGraphics, the framework Apple’s operating systems use to process images and other graphics content. The flaw is triggered by parsing a maliciously crafted file — no further detail on file type is given in the advisory, but the mechanism is memory corruption during processing rather than a logic or permissions bypass.
The CVSS vector (AV:N/AC:L/PR:N/UI:R) indicates the attack is delivered over the network, requires no privileges on the target, but does need the user to interact with the malicious file in some way — consistent with opening or previewing a document, image, or similar content that triggers CoreGraphics parsing. Successful exploitation leads to arbitrary code execution, with full impact to confidentiality, integrity, and availability.
This affects iOS, iPadOS, and macOS. Apple’s own notes state it has a report of exploitation “in an extremely sophisticated attack against specific targeted individuals” on iOS versions before iOS 27. The CVE is listed in CISA’s Known Exploited Vulnerabilities catalogue, added 29 September 2026.
What to do
- Update to the fixed releases named by Apple: iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1. Any device running an earlier build of these operating systems is affected.
- Prioritise iOS/iPadOS devices given Apple’s report of targeted exploitation on pre-iOS 27 builds; treat mobile fleet patching as urgent rather than routine.
- Because this is in CISA’s KEV catalogue, federal and regulated environments should follow applicable mandated remediation timelines; other organisations should treat it with equivalent urgency given the exploitation report.
- Since exploitation requires user interaction with a crafted file, reinforce standard caution around opening unsolicited attachments or links until fleets are patched, but do not rely on this as a substitute for patching.
- Consult Apple’s advisory directly for the exact build numbers and any platform-specific caveats not covered here.
For leadership 🧭
Executive summary. A flaw in how Apple devices process images and documents can let a single crafted file take over an iPhone, iPad or Mac, and Apple has confirmed a report of this being used in a targeted attack. Because it’s in CISA’s KEV catalogue, patching should happen this week, not at the next routine cycle.
Why it matters:
- The bug sits in CoreGraphics, the shared framework behind image and document rendering, so any app or workflow that previews or opens files on iOS, iPadOS or macOS can trigger it.
- Exploitation needs only that a user open or preview a malicious file — no admin rights, no additional bypass — and results in full code execution with complete loss of confidentiality, integrity and availability.
- Apple has reported exploitation against specific targeted individuals on iOS versions before iOS 27, meaning mobile devices carrying sensitive communications or credentials are the more urgent priority.
- Its presence in CISA’s KEV catalogue since 29 September 2026 means this is not theoretical risk assessment — remediation timelines apply for federal and regulated environments now.
Now / Next / Later:
- Now: Identify and prioritise patching of all iPhones and iPads still on builds before iOS 26.7.1 / iPadOS 26.7.1, given the reported targeted exploitation on pre-iOS 27 devices.
- Next: Roll out macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1 across managed Mac fleets in the next change window, treating any device below these builds as vulnerable.
- Later: Add CoreGraphics/OS build version checks to routine device compliance monitoring so future Apple security updates for this framework are tracked and enforced automatically rather than discovered ad hoc.