CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Apple iPadOS

product · product:apple-ipados

Coverage
1
first 2026-09-30 → last 2026-09-30
Latest activity
2026-09-30
Apple patches a CoreGraphics zero-day exploited against targeted iPhone users; a crafted file can lead to…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector
Sources cited
7
5 hosts

Action items (1)

Do-now tasks recorded on the entries about Apple iPadOS, newest first. Check the date before acting on an older one.

  • Push iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 through device management now, starting with the devices of staff who could be individually targeted; Apple describes the exploitation only on iOS before iOS 27.
    2026-09-30CVE-2026-86950

Defender insights

What each entry about Apple iPadOS tells a defender to do, newest first.

Story timeline

  1. 2026-09-30CVE-2026-86950, Apple iOS, iPadOS and macOS CoreGraphics: out-of-bounds write exploited in an extremely sophisticated attack on targeted iOS users, CISA KEV-listed (CVSS 8.8)
    trending-vulnerabilitiesApple patches a CoreGraphics zero-day exploited against targeted iPhone users; a crafted file can lead to code execution

Hunting pivots

CVEs (exploited first)
Releases covered
Apple iPadOS
ATT&CK techniques (1 across 1 tactic)

1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ExecutionExploitation for Client Execution

Execution TA0002

T1203Exploitation for Client Execution×1

Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.

Evidence: 2026-09-30/cve-2026-86950-apple-coregraphics-zero-day-kev · ATT&CK page ↗

Entries about Apple iPadOS (1)

2026-09-30 · view entry permalink →

HIGHCVE-2026-86950exploitedNATOA2

CVE-2026-86950, Apple iOS, iPadOS and macOS CoreGraphics: out-of-bounds write exploited in an extremely sophisticated attack on targeted iOS users, CISA KEV-listed (CVSS 8.8)

CVE-2026-86950 is an out-of-bounds write in CoreGraphics, the graphics component shared by iOS, iPadOS and macOS, and processing a maliciously crafted file can lead to arbitrary code execution (Apple, 2026-09-28). Apple states that it "is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27" (Apple, 2026-09-28). The fix, "improved bounds checking", ships in iOS and iPadOS 26.7.1 (Apple, 2026-09-28), macOS Tahoe 26.7.1 (Apple, 2026-09-28) and macOS Sequoia 15.8.1 (Apple, 2026-09-28); Meta Product Security is credited with the report. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-09-29 and attached its forensic-triage requirements to the listing (CISA, 2026-09-29). ENISA's vulnerability database scores it CVSS 3.1 8.8, network vector with user interaction required (ENISA EUVD, 2026-09-29). The macOS advisories repeat Apple's iOS-scoped exploitation sentence, so Apple does not claim exploitation on macOS.

Nothing about the attack itself is public: Apple gave no details on how many people were targeted, whether any attempt succeeded, or when exploitation began (The Hacker News, 2026-09-29), and no delivery mechanism is stated. SecurityWeek reads the component's role in 2D graphics and PDF rendering as meaning a file could arrive through web pages, email attachments or messaging apps, where automatic previews could allow zero-click exploitation; that is SecurityWeek's inference, and it also notes Meta would not say whether WhatsApp was involved (SecurityWeek, 2026-09-29). It also says iOS 27 and macOS Golden Gate 27 do not appear to be affected. No indicators or behavioural detections have been published by Apple, Meta or CISA, so version compliance is the only measurable lever: device-management inventory of iPhones and iPads still on the iOS 26 branch below 26.7.1, and of Macs on Tahoe or Sequoia below the fixed builds.

Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

An out-of-bounds write issue was addressed with improved bounds checking.

Apple Security

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

CISA Known Exploited Vulnerabilities Catalog 2026-09-29

the company offered no details on how many individuals were targeted, if any of those attempts were successful, or when the first instance of CVE-2026-86950 exploitation occurred

The Hacker News 2026-09-29
vulnerability30 Sep 04:40Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • support.apple.com3 (43%)
  • cisa.gov1 (14%)
  • euvd.enisa.europa.eu1 (14%)
  • securityweek.com1 (14%)
  • thehackernews.com1 (14%)