CVE-2026-86950 — Apple Multiple Products Out-of-Bounds Write Vulnerability

CVE-2026-86950

Apple CoreGraphics - Out-of-Bounds Write to Code Execution via a Crafted File

What is CoreGraphics?

CoreGraphics, historically called Quartz 2D, is the low-level drawing engine underneath almost everything visible on an Apple device. It handles path-based drawing, coordinate transformations, color management, offscreen rendering, patterns and gradients, and it decodes and rasterizes image and PDF data on behalf of higher-level frameworks. Every app that shows a photo, renders a PDF preview, or draws text ends up inside CoreGraphics code.

That ubiquity is what makes it valuable to an attacker. CoreGraphics parsing is reached without the user doing anything deliberate: a message attachment thumbnail, a web page image, a document preview in Quick Look or Mail. Parsers that run automatically on untrusted input, in a framework shared by every process on the system, are the classic starting point for a remote exploit chain, which is why Apple's image and font parsing code has produced repeated in-the-wild zero-days.

Overview

CVE-2026-86950 is an out-of-bounds write in CoreGraphics. Apple's advisory language is terse and consistent across platforms: "Processing a maliciously crafted file may lead to arbitrary code execution." The company fixed it with improved bounds checking and shipped the patch on 2026-09-28 in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.

Apple attached its standard exploitation notice: it is "aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." That phrasing is the wording Apple reserves for mercenary spyware and state-aligned intrusion activity rather than commodity malware. The iOS 27 line already contains the fix, so these releases are a backport for the large installed base still on the 26.x and Sequoia branches.

CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2026-09-29, one day after the patch, with a remediation deadline of 2026-10-02. The three-day window is unusually tight and reflects both the confirmed exploitation and the fact that a vendor patch is already available.

Affected Versions

Product Vulnerable Fixed
iOS (iPhone 11 and later) Before 26.7.1 26.7.1
iPadOS (iPad Pro 12.9-inch 3rd gen and later, iPad Pro 11-inch 1st gen and later, iPad Air 3rd gen and later, iPad 8th gen and later, iPad mini 5th gen and later) Before 26.7.1 26.7.1
macOS Tahoe Before 26.7.1 26.7.1
macOS Sequoia Before 15.8.1 15.8.1
iOS / iPadOS 27 Not affected Not applicable

Technical Details

The weakness is CWE-787, an out-of-bounds write. In plain terms, CoreGraphics allocates a buffer sized from one part of a file and then writes into it using a length or offset taken from another part, without checking that the write stays inside the allocation. A crafted file drives that write past the end of the buffer and corrupts whatever memory sits next to it. Attacker-controlled corruption of adjacent heap objects is the standard route to hijacking a function pointer or object vtable and redirecting execution.

The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, base score 8.8. Network vector, no privileges, low complexity, but user interaction required: something has to hand the malicious file to the framework. In practice that bar is low, since preview generation and automatic image rendering count.

Apple has published no detail on the file format involved, the specific parser, or which process the exploit lands in. Neither Apple nor Meta has released technical analysis, and no proof-of-concept is public. On its own an out-of-bounds write in a sandboxed rendering process is not a full compromise, so a working intrusion almost certainly chained this with a sandbox escape and a kernel privilege escalation; no such companion CVEs have been named.

Discovery

Apple credits Meta Product Security in all three advisories. Meta has not published a write-up, and neither party has said how the bug surfaced, whether through proactive review, telemetry from Meta's own messaging platforms, or victim device analysis. Reporting organizations that find a bug already under active exploitation typically find it in the second way, and Apple's wording, a report that the issue "may have been exploited," is consistent with attribution arriving alongside the bug report rather than from Apple's own detection.

Exploitation Context

Apple confirms targeted exploitation and says nothing further. There is no named threat actor, no victim count, no campaign name, no targeted sector, and no delivery vector confirmed by any source. CISA does not flag the CVE as used in ransomware campaigns. Exposure counts of the kind published for server-side flaws do not apply here, since the affected population is every unpatched Apple client device.

Sources disagree on how many exploited zero-days Apple has patched in 2026: BleepingComputer counts this as the second, while The Register calls it the seventh. The discrepancy is most likely a difference in what each counts, and the number should not be treated as settled. The clearer comparison point is CVE-2026-20700, a dyad memory corruption flaw Apple patched in February 2026 that was likewise described as used in sophisticated attacks.

The practical reading for defenders: exploitation is real but narrow today. The risk profile changes once the patch is diffed, because a fix described as "improved bounds checking" tends to make the vulnerable path obvious to anyone comparing binaries.

Remediation

  1. Update to iOS 26.7.1 or iPadOS 26.7.1 on mobile devices, macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1 on Macs. Devices already on iOS or iPadOS 27 need no action for this CVE.
  2. Push the update through MDM rather than relying on user-initiated installs, and confirm compliance by build number. Federal civilian agencies were required to remediate by 2026-10-02 under BOD 26-04.
  3. Enable automatic updates on any device outside MDM management, including personally owned devices under a BYOD program.
  4. For individuals plausibly in scope for targeted attacks, journalists, activists, executives, government staff, turn on Lockdown Mode. It disables or restricts much of the automatic file and image handling that a CoreGraphics exploit needs to reach its parser.
  5. There is no vendor workaround and no configuration change that mitigates this short of patching. Network controls do not help, because the malicious file arrives over whatever channel the user already uses.
  6. For suspected targets, check Apple threat notifications on the Apple ID account, review the device for unexpected profiles, configuration changes or unfamiliar apps, and preserve a sysdiagnose before wiping. Escalate to a forensics team rather than triaging in place, since a full reset destroys the evidence of what happened.
  7. Watch for follow-up reporting. If Meta or a research group publishes the chain this was part of, the companion sandbox escape and kernel bugs will matter as much as this one.

Key Details

PropertyValue
CVE ID CVE-2026-86950
Vendor / Product Apple — Multiple Products
NVD Published2026-09-28
NVD Last Modified2026-09-29
CVSS 3.1 Score8.8
CVSS 3.1 VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
SeverityHIGH
CWE CWE-787 find similar ↗
CISA KEV Added2026-09-29
CISA KEV Deadline2026-10-02
Known Ransomware Use No

CVSS 3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Required Action

CISA BOD 22-01 Deadline: 2026-10-02. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Timeline

DateEvent
2026-09-28Apple ships iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, crediting Meta Product Security
2026-09-28CVE-2026-86950 published
2026-09-29Added to CISA Known Exploited Vulnerabilities catalog
2026-10-02CISA BOD 26-04 remediation deadline