What it is
CVE-2026-86950 is an unauthenticated vulnerability affecting Apple iOS and iPadOS, macOS. An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1,...
Vulnerability report
iOS and iPadOS
Apple / iOS and iPadOS · affected before 26.7.1
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-86950 is an unauthenticated vulnerability affecting Apple iOS and iPadOS, macOS. An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1,...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Apple / iOS and iPadOS affected before 26.7.1.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1.
Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
CVE
A trusted third party reported exploitation.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CVE First | 2026-09-28 19:30 UTC |
| The Hacker News | 2026-09-28 19:30 UTC |
| CyberInsider | 2026-09-29 10:20 UTC |
| Qualys ThreatPROTECT | 2026-09-29 14:20 UTC |
| CISA | 2026-09-29 14:20 UTC |
| Security Affairs | 2026-09-29 15:20 UTC |
| SOCRadar | 2026-10-01 07:20 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
1.2%
Recent mention · Security Affairs
Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that attackers may have exploited to target specific...
Read full advisoryRecent mention · Security Affairs
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950Security Affairs · 01 Oct 2026
Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that attackers may have exploited to target specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when […]
Recent mention · The Hacker News
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery PathThe Hacker News · 01 Oct 2026
Swati KhandelwalOct 01, 2026Vulnerability / Mobile Security Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working exploit is separate work the analysis does not demonstrate. Apple patched the flaw on September 28, crediting Meta Product Security with the...
Recent mention · SOCRadar
CVE-2026-86950: Apple CoreGraphics Zero-DaySOCRadar · 30 Sep 2026
CVE-2026-86950: Apple CoreGraphics Zero-Day Apple has issued an urgent security patch for CVE-2026-86950 , a critical zero-day out-of-bounds write vulnerability in CoreGraphics that enables arbitrary code execution via m
Recent mention · Security Affairs
U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs · 30 Sep 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Apple has released security updates for iOS, iPadOS […]
Recent mention · Dark Reading
Apple Zero-Day Vulnerability Weaponized in Targeted AttacksDark Reading · 29 Sep 2026
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
Recent mention · TheRegister
Apple patches CoreGraphics zero-day already exploited in targeted attacksTheRegister · 29 Sep 2026
Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file
Recent mention · Qualys ThreatPROTECT
Apple Warns Users iOS Vulnerability Exploited in Attack (CVE-2026-86950)Qualys ThreatPROTECT · 29 Sep 2026
Apple released updates to address an actively exploited vulnerability tracked as CVE-2026-86950. The vulnerability affects iOS, iPadOS, macOS Tahoe, and Sequoia. This is an out-of-bounds write flaw that can be exploited by processing a maliciously crafted file. Successful exploitation of the vulnerability may lead to arbitrary code execution. Apple has addressed the vulnerability with improved bounds checking. Apple mentioned in … Continue reading "Apple Warns Users iOS Vulnerability Exploited in Attack (CVE-2026-86950)"
Recent mention · Security Affairs
Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted AttacksSecurity Affairs · 29 Sep 2026
Apple patched zero-day CVE-2026-86950 in CoreGraphics, exploited in sophisticated targeted attacks against specific iOS users. Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to […]
Recent mention · CyberInsider
Apple patches CoreGraphics flaw linked to targeted iPhone attacksCyberInsider · 29 Sep 2026
Apple has released security updates for iPhones, iPads, and Macs to fix a CoreGraphics vulnerability that may have been exploited in a highly targeted attack. The flaw, tracked as CVE-2026-86950, could allow arbitrary code execution when a device processes a maliciously crafted file. In its security advisory, Apple said it was aware of a report … The post Apple patches CoreGraphics flaw linked to targeted iPhone attacks appeared first on CyberInsider.
Recent mention · Full Disclosure Mailinglist
APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1Full Disclosure Mailinglist · 29 Sep 2026
Posted by Apple Product Security via Fulldisclosure on Sep 28APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1 macOS Sequoia 15.8.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/149229. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. CoreGraphics Available for: macOS Sequoia Impact: Processing a maliciously crafted file may lead to arbitrary code...
Recent mention · Full Disclosure Mailinglist
APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1Full Disclosure Mailinglist · 29 Sep 2026
Posted by Apple Product Security via Fulldisclosure on Sep 28APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1 macOS Tahoe 26.7.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/149228. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. CoreGraphics Available for: macOS Tahoe Impact: Processing a maliciously crafted file may lead to arbitrary code...
Recent mention · Full Disclosure Mailinglist
APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1Full Disclosure Mailinglist · 29 Sep 2026
Posted by Apple Product Security via Fulldisclosure on Sep 28APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1 iOS 26.7.1 and iPadOS 26.7.1 addresses the following issues. Information about the security content is also available at https://support.apple.com/149226. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. CoreGraphics Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro...
Recent mention · The Hacker News
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted AttacksThe Hacker News · 28 Sep 2026
Ravie LakshmananSep 28, 2026Vulnerability / Endpoint Security Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the issue was addressed with improved bounds checking. It credited Meta Product Security with discovering and reporting the issue. "Apple is...
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-09-29 08:46:38 UTC · 0 stars · AI assessment 85%
Out-of-bounds Write (CWE-787)
Timeline
07:20 UTC
Exploitation attested by an external source
15:20 UTC
Exploitation attested by an external source
14:20 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
14:20 UTC
Exploitation attested by an external source
10:20 UTC
Exploitation attested by an external source
08:46 UTC
Public proof-of-concept code published
19:30 UTC
Exploitation attested by an external source
19:30 UTC
High-confidence, third-party attested exploitation
19:13 UTC
Vulnerability disclosed publicly
16:43 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-86950
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-86950",
"confidence": "Confirmed",
"cvss_score": 8.8,
"cvss_estimated": false,
"epss_score": 0.01242,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}