
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-86950 is an out-of-bounds write vulnerability in Apple's CoreGraphics framework affecting iOS, iPadOS, and macOS. Processing a maliciously crafted file can trigger arbitrary code execution. The flaw was reported by Meta Product Security and disclosed by Apple on September 28, 2026, with patches released the same day. Affected versions include iOS and iPadOS before 26.7.1, macOS Sequoia before 15.8.1, and macOS Tahoe before 26.7.1. Apple confirmed active exploitation in "an extremely sophisticated attack against specific targeted individuals" on iOS versions prior to iOS 27. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Apple Advisory iOS, Apple Advisory macOS Tahoe, Apple Advisory macOS Sequoia, GitHub Advisory).
The vulnerability is classified as CWE-787 (Out-of-bounds Write) and resides in Apple's CoreGraphics framework, which handles rendering and image/file processing. Insufficient bounds checking during the parsing of a maliciously crafted file allows an attacker to write data beyond the bounds of an allocated buffer, potentially corrupting memory in a way that leads to arbitrary code execution. Exploitation requires user interaction — specifically, a target must open or process a maliciously crafted file (e.g., a PDF or image), making it a network-delivered, user-interaction-required attack vector. Subsequent reporting indicated that WhatsApp PDF delivery was investigated as a possible delivery path, and a public proof-of-concept emerged shortly after disclosure (Apple Advisory iOS, The Hacker News, GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the victim's device with the privileges of the application processing the malicious file. The impact spans high confidentiality, integrity, and availability — an attacker could access sensitive data (including potentially cryptocurrency wallet credentials, as warned by SlowMist), modify or destroy data, and render the device unstable. Given the targeted nature of confirmed exploitation, high-value individuals such as journalists, activists, or executives are at elevated risk, and the attack could serve as an initial access vector for further device compromise or spyware deployment (Apple Advisory iOS, CISA KEV, Lookout).
CVE-2026-86950 is confirmed as actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on September 29, 2026, with a remediation due date of October 2, 2026. Apple explicitly acknowledged exploitation in "an extremely sophisticated attack" against targeted individuals on iOS versions prior to iOS 27. The vulnerability was reported by Meta Product Security, suggesting possible discovery during threat intelligence or incident response activities. A public proof-of-concept emerged on GitHub (attributed to 0xBlackash) around October 5, 2026, and a detection tool (detect_CVE-2026-86950) was also published. A separate GitHub repository claiming a PoC was assessed as a fake/scam (no actual exploit code, paywall-gated). The EPSS score is approximately 1.24% (68th percentile), reflecting elevated exploitation probability relative to most CVEs (CISA KEV, Apple Advisory iOS, GitHub Advisory).
detect_CVE-2026-86950 (available at https://github.com/decalage2/detect_CVE-2026-86950) was published to assist defenders in identifying signs of exploitation (CISA KEV, Security Affairs).Apple released patches on September 28, 2026: iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. CISA mandated that federal agencies apply these mitigations by October 2, 2026, per BOD 26-04. All users running affected versions should update immediately via Settings > General > Software Update (iOS/iPadOS) or System Settings > General > Software Update (macOS). As a precautionary measure, users should avoid opening files from untrusted or unexpected sources until patched. No configuration-based workaround is available — patching is the only effective remediation (Apple Advisory iOS, Apple Advisory macOS Tahoe, Apple Advisory macOS Sequoia, CISA KEV).
Apple's advisory credited Meta Product Security for discovering and reporting the vulnerability, which drew significant attention given the cross-company nature of the disclosure and speculation about the delivery vector involving WhatsApp. Security researchers and media widely covered the vulnerability as a high-profile zero-day, with Forbes, TechCrunch, BleepingComputer, The Register, SecurityWeek, and Computerworld all publishing urgent update warnings. SlowMist issued a specific warning that the flaw could put cryptocurrency wallet data at risk, amplifying concern in the crypto community. The SANS Internet Storm Center published an emergency patch diary entry, and multiple national CERTs (HKCERT, Canadian CCCS, Australian WA SOC, Thai ThaiCERT, UK NHS) issued advisories. Community discussion on Reddit and Mastodon was active, with some users noting the irony of a Meta-reported Apple zero-day and debating the sophistication of the attack chain. The vulnerability was described by some researchers as potentially spyware-related given its targeted nature (The Hacker News, SecurityWeek, Help Net Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."