CVE-2026-86950 · CVSS 8.8 HIGH · KEV 2026-09-29 · patch available
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Is CVE-2026-86950 exploited?
Listed in the CISA KEV catalog on 2026-09-29.
Federal remediation due 2026-10-02.
Public exploit code: none found in monitored sources.