CVE-2026-86950: 
macOS vulnerability analysis and mitigation

Overview

CVE-2026-86950 is an out-of-bounds write vulnerability in Apple's CoreGraphics framework affecting iOS, iPadOS, and macOS. Processing a maliciously crafted file can trigger arbitrary code execution. The flaw was reported by Meta Product Security and disclosed by Apple on September 28, 2026, with patches released the same day. Affected versions include iOS and iPadOS before 26.7.1, macOS Sequoia before 15.8.1, and macOS Tahoe before 26.7.1. Apple confirmed active exploitation in "an extremely sophisticated attack against specific targeted individuals" on iOS versions prior to iOS 27. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Apple Advisory iOS, Apple Advisory macOS Tahoe, Apple Advisory macOS Sequoia, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write) and resides in Apple's CoreGraphics framework, which handles rendering and image/file processing. Insufficient bounds checking during the parsing of a maliciously crafted file allows an attacker to write data beyond the bounds of an allocated buffer, potentially corrupting memory in a way that leads to arbitrary code execution. Exploitation requires user interaction — specifically, a target must open or process a maliciously crafted file (e.g., a PDF or image), making it a network-delivered, user-interaction-required attack vector. Subsequent reporting indicated that WhatsApp PDF delivery was investigated as a possible delivery path, and a public proof-of-concept emerged shortly after disclosure (Apple Advisory iOS, The Hacker News, GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the victim's device with the privileges of the application processing the malicious file. The impact spans high confidentiality, integrity, and availability — an attacker could access sensitive data (including potentially cryptocurrency wallet credentials, as warned by SlowMist), modify or destroy data, and render the device unstable. Given the targeted nature of confirmed exploitation, high-value individuals such as journalists, activists, or executives are at elevated risk, and the attack could serve as an initial access vector for further device compromise or spyware deployment (Apple Advisory iOS, CISA KEV, Lookout).

Exploitability

CVE-2026-86950 is confirmed as actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on September 29, 2026, with a remediation due date of October 2, 2026. Apple explicitly acknowledged exploitation in "an extremely sophisticated attack" against targeted individuals on iOS versions prior to iOS 27. The vulnerability was reported by Meta Product Security, suggesting possible discovery during threat intelligence or incident response activities. A public proof-of-concept emerged on GitHub (attributed to 0xBlackash) around October 5, 2026, and a detection tool (detect_CVE-2026-86950) was also published. A separate GitHub repository claiming a PoC was assessed as a fake/scam (no actual exploit code, paywall-gated). The EPSS score is approximately 1.24% (68th percentile), reflecting elevated exploitation probability relative to most CVEs (CISA KEV, Apple Advisory iOS, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify high-value targets (e.g., journalists, executives, activists) running iOS 26.x (prior to 26.7.1) or macOS Sequoia/Tahoe prior to patched versions, using OSINT or prior intelligence.
  2. Craft malicious file: Prepare a specially crafted file (e.g., a PDF or image) that triggers the CoreGraphics out-of-bounds write vulnerability when parsed. The file is engineered to corrupt memory in a controlled manner to redirect code execution.
  3. Deliver the payload: Deliver the malicious file to the target via a messaging platform (WhatsApp PDF delivery was investigated as a possible vector), email attachment, or web-based download — requiring the target to open or preview the file.
  4. Trigger exploitation: When the target's device processes the malicious file through CoreGraphics, the out-of-bounds write occurs, corrupting adjacent memory structures and enabling control of the instruction pointer.
  5. Achieve arbitrary code execution: The attacker's shellcode or payload executes in the context of the processing application, potentially enabling spyware installation, credential theft, or persistent access to the device (Apple Advisory iOS, The Hacker News, Security Affairs).

Indicators of compromise

  • Network: Unexpected outbound connections from iOS/macOS devices to unknown or suspicious IP addresses following file receipt or preview; anomalous data exfiltration patterns from mobile devices.
  • File System: Presence of unexpected or unsigned processes spawned after opening a PDF or image file; unusual files written to application sandbox directories or temporary folders by CoreGraphics-related processes.
  • Logs: Crash logs or system logs referencing CoreGraphics memory access violations or out-of-bounds write errors around the time a suspicious file was opened; unexpected process launches following file parsing events.
  • Process Behavior: Unusual child processes spawned by file-viewing applications (e.g., Mail, Messages, WhatsApp) on iOS or macOS; processes executing with elevated privileges unexpectedly after file interaction.
  • Detection Tools: The open-source tool detect_CVE-2026-86950 (available at https://github.com/decalage2/detect_CVE-2026-86950) was published to assist defenders in identifying signs of exploitation (CISA KEV, Security Affairs).

Mitigation and workarounds

Apple released patches on September 28, 2026: iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. CISA mandated that federal agencies apply these mitigations by October 2, 2026, per BOD 26-04. All users running affected versions should update immediately via Settings > General > Software Update (iOS/iPadOS) or System Settings > General > Software Update (macOS). As a precautionary measure, users should avoid opening files from untrusted or unexpected sources until patched. No configuration-based workaround is available — patching is the only effective remediation (Apple Advisory iOS, Apple Advisory macOS Tahoe, Apple Advisory macOS Sequoia, CISA KEV).

Community reactions

Apple's advisory credited Meta Product Security for discovering and reporting the vulnerability, which drew significant attention given the cross-company nature of the disclosure and speculation about the delivery vector involving WhatsApp. Security researchers and media widely covered the vulnerability as a high-profile zero-day, with Forbes, TechCrunch, BleepingComputer, The Register, SecurityWeek, and Computerworld all publishing urgent update warnings. SlowMist issued a specific warning that the flaw could put cryptocurrency wallet data at risk, amplifying concern in the crypto community. The SANS Internet Storm Center published an emergency patch diary entry, and multiple national CERTs (HKCERT, Canadian CCCS, Australian WA SOC, Thai ThaiCERT, UK NHS) issued advisories. Community discussion on Reddit and Mastodon was active, with some users noting the irony of a Meta-reported Apple zero-day and debating the sophistication of the attack chain. The vulnerability was described by some researchers as potentially spyware-related given its targeted nature (The Hacker News, SecurityWeek, Help Net Security).

Additional resources


Source: This report was generated using AI

Related macOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86950HIGH8.8
  • macOS logomacOS
  • CoreGraphics
YesYesSep 28, 2026
CVE-2026-86917HIGH7.8
  • macOS logomacOS
  • Kernel
NoYesSep 14, 2026
CVE-2026-86924MEDIUM5.5
  • macOS logomacOS
  • MobileAccessoryUpdater
NoYesSep 14, 2026
CVE-2026-86910MEDIUM5.5
  • macOS logomacOS
  • APFS
NoYesSep 14, 2026
CVE-2026-86902MEDIUM5.5
  • macOS logomacOS
  • NSDocument
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management