High severity8.8NVD Advisory· Published Sep 28, 2026· Updated Sep 28, 2026
CVE-2026-86950
CVE-2026-86950
Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Affected products
3- Range: <15.8.1 and <26.7.1
- Range: <26.7.1
- Range: <27, and <=26.7.1
Patches
Vulnerability mechanics
References
3News mentions
2- Apple Emergency Patch for iOS 26/macOS26/macOS15 (CVE-2026-86950), (Mon, Sep 28th)SANS Internet Storm Center · Sep 28, 2026
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted AttacksThe Hacker News · Sep 28, 2026