Vulnerability report

Exploited in the wild Confirmed confidence In CISA KEV

CVE-2026-86950

iOS and iPadOS

Apple / iOS and iPadOS · affected before 26.7.1

Severity
CVSS 8.8 · High
Confidence
Confirmed
Exploit status
Exploited in the wild
EPSS
1.2%
First observed
—
Last observed
—

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2026-86950 is an unauthenticated vulnerability affecting Apple iOS and iPadOS, macOS. An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1,...

Is it exploited?

Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.

Who is affected?

Apple / iOS and iPadOS affected before 26.7.1.

What should we do?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Overview

An out-of-bounds write issue was addressed with improved bounds checking

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1.

Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Apple Affected
iOS and iPadOS
Before 26.7.1
Apple Affected
macOS
Before 15.8.1 Before 26.7.1
Published
28 Sep 2026
Exploitation Reported
28 Sep 2026
Attack vector
Remote
Complexity
Low
Privileges
None
User interaction
Required

Tags

macos ios cisa

CVE References

Exploitation evidence

Why Previdian marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

CVE

Recorded 28 Sep 2026

A trusted third party reported exploitation.

Proof of concept available

GitHub

Recorded 29 Sep 2026

Public scanner or PoC coverage increases practical exploitability.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the Previdian Pro API.

Learn about Pro API access
Source Added
CVE First 2026-09-28 19:30 UTC
The Hacker News 2026-09-28 19:30 UTC
CyberInsider 2026-09-29 10:20 UTC
Qualys ThreatPROTECT 2026-09-29 14:20 UTC
CISA 2026-09-29 14:20 UTC
Security Affairs 2026-09-29 15:20 UTC
SOCRadar 2026-10-01 07:20 UTC

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
User-Agents
Callback hosts
0
0
0

Request targets and User-Agents available in Pro. Callback host details available in Enterprise.

Scanner coverage

No scanner integrations recorded yet.

Virtual patch status

No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

No detection artifacts or sensor request patterns are available for this CVE yet.

Check back as sensor telemetry and scanner integrations are updated.

Risk and context

Severity, weaknesses, and research context

CVSS v3.1

8.8 High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

1.2%

Recent mention · Security Affairs

Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950

Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that attackers may have exploited to target specific...

Read full advisory

All Mentions

Recent mention · Security Affairs

Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950

Security Affairs · 01 Oct 2026

Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that attackers may have exploited to target specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when […]

Recent mention · The Hacker News

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

The Hacker News · 01 Oct 2026

Swati KhandelwalOct 01, 2026Vulnerability / Mobile Security Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working exploit is separate work the analysis does not demonstrate. Apple patched the flaw on September 28, crediting Meta Product Security with the...

Recent mention · SOCRadar

CVE-2026-86950: Apple CoreGraphics Zero-Day

SOCRadar · 30 Sep 2026

CVE-2026-86950: Apple CoreGraphics Zero-Day Apple has issued an urgent security patch for CVE-2026-86950 , a critical zero-day out-of-bounds write vulnerability in CoreGraphics that enables arbitrary code execution via m

Recent mention · Security Affairs

U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

Security Affairs · 30 Sep 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Apple has released security updates for iOS, iPadOS […]

Recent mention · Dark Reading

Apple Zero-Day Vulnerability Weaponized in Targeted Attacks

Dark Reading · 29 Sep 2026

Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.

Recent mention · TheRegister

Apple patches CoreGraphics zero-day already exploited in targeted attacks

TheRegister · 29 Sep 2026

Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file

Recent mention · Qualys ThreatPROTECT

Apple Warns Users iOS Vulnerability Exploited in Attack (CVE-2026-86950)

Qualys ThreatPROTECT · 29 Sep 2026

Apple released updates to address an actively exploited vulnerability tracked as CVE-2026-86950. The vulnerability affects iOS, iPadOS, macOS Tahoe, and Sequoia. This is an out-of-bounds write flaw that can be exploited by processing a maliciously crafted file. Successful exploitation of the vulnerability may lead to arbitrary code execution. Apple has addressed the vulnerability with improved bounds checking. Apple mentioned in … Continue reading "Apple Warns Users iOS Vulnerability Exploited in Attack (CVE-2026-86950)"

Recent mention · Security Affairs

Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks

Security Affairs · 29 Sep 2026

Apple patched zero-day CVE-2026-86950 in CoreGraphics, exploited in sophisticated targeted attacks against specific iOS users. Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to […]

Recent mention · CyberInsider

Apple patches CoreGraphics flaw linked to targeted iPhone attacks

CyberInsider · 29 Sep 2026

Apple has released security updates for iPhones, iPads, and Macs to fix a CoreGraphics vulnerability that may have been exploited in a highly targeted attack. The flaw, tracked as CVE-2026-86950, could allow arbitrary code execution when a device processes a maliciously crafted file. In its security advisory, Apple said it was aware of a report … The post Apple patches CoreGraphics flaw linked to targeted iPhone attacks appeared first on CyberInsider.

Recent mention · Full Disclosure Mailinglist

APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1

Full Disclosure Mailinglist · 29 Sep 2026

Posted by Apple Product Security via Fulldisclosure on Sep 28APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1 macOS Sequoia 15.8.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/149229. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. CoreGraphics Available for: macOS Sequoia Impact: Processing a maliciously crafted file may lead to arbitrary code...

Recent mention · Full Disclosure Mailinglist

APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1

Full Disclosure Mailinglist · 29 Sep 2026

Posted by Apple Product Security via Fulldisclosure on Sep 28APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1 macOS Tahoe 26.7.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/149228. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. CoreGraphics Available for: macOS Tahoe Impact: Processing a maliciously crafted file may lead to arbitrary code...

Recent mention · Full Disclosure Mailinglist

APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1

Full Disclosure Mailinglist · 29 Sep 2026

Posted by Apple Product Security via Fulldisclosure on Sep 28APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1 iOS 26.7.1 and iPadOS 26.7.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/149226. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. CoreGraphics Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro...

Recent mention · The Hacker News

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

The Hacker News · 28 Sep 2026

Ravie LakshmananSep 28, 2026Vulnerability / Endpoint Security Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the issue was addressed with improved bounds checking. It credited Meta Product Security with discovering and reporting the issue. "Apple is...

Potential Proof of Concepts

These PoCs are unverified and could contain malware. Use at your own risk.

DeAurity/CVE-2026-86950-POC

github · Created 2026-09-29 08:46:38 UTC · 0 stars · AI assessment 85%

Out-of-bounds Write (CWE-787)

Timeline

From disclosure to observed exploitation

  1. 07:20 UTC

    KEV confirmed by SOCRadar

    Exploitation attested by an external source

  2. 15:20 UTC

    KEV confirmed by Security Affairs

    Exploitation attested by an external source

  3. 14:20 UTC

    Added to CISA KEV

    Listed in the CISA Known Exploited Vulnerabilities catalog

  4. 14:20 UTC

    KEV confirmed by Qualys ThreatPROTECT

    Exploitation attested by an external source

  5. 10:20 UTC

    KEV confirmed by CyberInsider

    Exploitation attested by an external source

  6. 08:46 UTC

    Public PoC available

    Public proof-of-concept code published

  7. 19:30 UTC

    KEV confirmed by The Hacker News

    Exploitation attested by an external source

  8. 19:30 UTC

    Added to Previdian KEV Feed

    High-confidence, third-party attested exploitation

  9. 19:13 UTC

    CVE published

    Vulnerability disclosed publicly

  10. 16:43 UTC

    CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2026-86950

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2026-86950",
  "confidence": "Confirmed",
  "cvss_score": 8.8,
  "cvss_estimated": false,
  "epss_score": 0.01242,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": false
  },
  "sensor_telemetry": { "attempts": 0, "sensors": 0 }
}