---
schema: 1
kind: vulnerability
title: "CVE-2026-86950, Apple iOS, iPadOS and macOS CoreGraphics: out-of-bounds write exploited in an extremely sophisticated attack on targeted iOS users, CISA KEV-listed (CVSS 8.8)"
headline: "Apple patches a CoreGraphics zero-day exploited against targeted iPhone users; a crafted file can lead to code execution"
summary: >
  Apple's 2026-09-28 updates (iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1) fix
  CVE-2026-86950, a CoreGraphics out-of-bounds write that can run arbitrary code when a crafted file is
  processed. Apple says it may have been exploited in an extremely sophisticated attack against specific
  targeted individuals on versions of iOS before iOS 27, and CISA added it to the KEV catalog on 2026-09-29.
  No source states how the file is delivered.
discovered_at: "2026-09-30T04:40:00Z"
updated_at: null
event_date: "2026-09-28"
run_id: 2026-09-30T0404Z-intel
priority: high
immediate_action: null
tags: [vulnerabilities, zero-day, actively-exploited, cisa-kev, patch-available, mobile, rce]
regions: [global]
sectors: [public-sector]
entities: ["product:apple-ios", "product:apple-ipados", "product:apple-macos"]
techniques: [T1203]
affected_products: ["Apple iOS", "Apple iPadOS", "Apple macOS"]
cves:
  - id: CVE-2026-86950
    cvss: "8.8"
    epss: "0.81"
    type: memory-corruption
    vector: user-interaction
    auth: pre-auth
    status: [exploited, cisa-kev, patch-available]
    affected: "iOS and iPadOS before 26.7.1; macOS Tahoe before 26.7.1; macOS Sequoia before 15.8.1 (Apple describes the exploitation only for iOS before iOS 27)"
    fixed: "iOS 26.7.1 and iPadOS 26.7.1; macOS Tahoe 26.7.1; macOS Sequoia 15.8.1"
sources:
  - url: "https://support.apple.com/en-us/149226"
    publisher: "Apple Security (iOS 26.7.1 and iPadOS 26.7.1)"
    date: "2026-09-28"
    role: primary
  - url: "https://support.apple.com/en-us/149228"
    publisher: "Apple Security (macOS Tahoe 26.7.1)"
    date: "2026-09-28"
    role: primary
  - url: "https://support.apple.com/en-us/149229"
    publisher: "Apple Security (macOS Sequoia 15.8.1)"
    date: "2026-09-28"
    role: primary
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA Known Exploited Vulnerabilities Catalog"
    date: "2026-09-29"
    role: primary
  - url: "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88445"
    publisher: "ENISA EU Vulnerability Database"
    date: "2026-09-29"
    role: corroborating
  - url: "https://www.securityweek.com/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack/"
    publisher: "SecurityWeek"
    date: "2026-09-29"
    role: corroborating
  - url: "https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html"
    publisher: "The Hacker News"
    date: "2026-09-29"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."
    publisher: "Apple Security"
    source_url: "https://support.apple.com/en-us/149226"
  - quote: "An out-of-bounds write issue was addressed with improved bounds checking."
    publisher: "Apple Security"
    source_url: "https://support.apple.com/en-us/149226"
  - quote: "Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution."
    publisher: "CISA Known Exploited Vulnerabilities Catalog"
    source_url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
  - quote: "the company offered no details on how many individuals were targeted, if any of those attempts were successful, or when the first instance of CVE-2026-86950 exploitation occurred"
    publisher: "The Hacker News"
    source_url: "https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html"
verification: multi-source
sourcing_note: >
  Exploitation is Apple's own report, carried into the CISA KEV listing; no independent telemetry has been published.
  The CVSS score is ENISA's record of the CVE; Apple's advisories carry none.
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "Push iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 through device management now, starting with the devices of staff who could be individually targeted; Apple describes the exploitation only on iOS before iOS 27."
updates: []
migrated_from: null
---

CVE-2026-86950 is an out-of-bounds write in CoreGraphics, the graphics component shared by iOS, iPadOS and macOS, and processing a maliciously crafted file can lead to arbitrary code execution ([Apple, 2026-09-28](https://support.apple.com/en-us/149226)). Apple states that it "is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27" ([Apple, 2026-09-28](https://support.apple.com/en-us/149226)). The fix, "improved bounds checking", ships in iOS and iPadOS 26.7.1 ([Apple, 2026-09-28](https://support.apple.com/en-us/149226)), macOS Tahoe 26.7.1 ([Apple, 2026-09-28](https://support.apple.com/en-us/149228)) and macOS Sequoia 15.8.1 ([Apple, 2026-09-28](https://support.apple.com/en-us/149229)); Meta Product Security is credited with the report. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-09-29 and attached its forensic-triage requirements to the listing ([CISA, 2026-09-29](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)). ENISA's vulnerability database scores it CVSS 3.1 8.8, network vector with user interaction required ([ENISA EUVD, 2026-09-29](https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88445)). The macOS advisories repeat Apple's iOS-scoped exploitation sentence, so Apple does not claim exploitation on macOS.

Nothing about the attack itself is public: Apple gave no details on how many people were targeted, whether any attempt succeeded, or when exploitation began ([The Hacker News, 2026-09-29](https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html)), and no delivery mechanism is stated. SecurityWeek reads the component's role in 2D graphics and PDF rendering as meaning a file could arrive through web pages, email attachments or messaging apps, where automatic previews could allow zero-click exploitation; that is SecurityWeek's inference, and it also notes Meta would not say whether WhatsApp was involved ([SecurityWeek, 2026-09-29](https://www.securityweek.com/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack/)). It also says iOS 27 and macOS Golden Gate 27 do not appear to be affected. No indicators or behavioural detections have been published by Apple, Meta or CISA, so version compliance is the only measurable lever: device-management inventory of iPhones and iPads still on the iOS 26 branch below 26.7.1, and of Macs on Tahoe or Sequoia below the fixed builds.

**Defender takeaway:** Apple describes an attack on specific targeted individuals, so the staff an adversary would single out are the first whose devices need the update. A device that ran a vulnerable build is not evidence of compromise, and no published signature exists to check for one.
