CVE-2026-86950
Known exploited · CISA KEV
CVSS 8.8 HIGH: an out-of-bounds write issue was addressed with improved bounds checking.
CISA federal remediation date Oct 2
Vulnerabilities & Exploits · Zero-Day Exploit
CSIRT Italia and Apple say CVE-2026-86950 is being exploited in the wild, moving the CoreGraphics zero-day from a vendor patch to a live attack on iPhone, iPad, and Mac fleets. Apple has already shipped iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.
The bug is an out-of-bounds write in CoreGraphics, the graphics code that renders images and PDFs. A specially crafted file can make the engine write past the memory it was given, which can lead to arbitrary code execution when a device opens or previews the content; that makes ordinary mail, chat, web, or attachment handling the attack path, not an obvious installer or login.
CISA’s KEV listing and the national CERT confirmation compress this into a days-not-weeks problem for Apple fleets. If users routinely preview shared content on managed devices, the exposure sits in the content-processing layer itself, and the remaining question is how widely the exploit has spread, not whether the flaw is live.
8 sources · Sep 30
Known exploited · CISA KEV
CVSS 8.8 HIGH: an out-of-bounds write issue was addressed with improved bounds checking.
CISA federal remediation date Oct 2
Dark Reading
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
originalThe Register Security
Apple patches CoreGraphics zero-day already exploited in targeted attacks
Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file
originalTechCrunch Security
Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix | TechCrunch
Apple says the bug was used to attack "specific targeted individuals" running iOS 26, which the majority of Apple customers are still using.
originalPart of the PlainSec briefing for 2026-09-28
Every edition of this story: Apple CoreGraphics Zero-Day Is Now in the Wild