CVE-2026-86950
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: an out-of-bounds write issue was addressed with improved bounds checking.
Data di correzione federale CISA 2 ott
Vulnerabilità ed exploit · Exploit zero-day
Apple ha corretto CVE-2026-86950 su iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 e macOS Sequoia 15.8.1, ma il punto della storia è cambiato: CSIRT Italia conferma lo sfruttamento in rete e CISA lo ha inserito nel catalogo KEV. Per chi gestisce flotte Apple, la correzione non è più una normale notifica di patch ma una corsa contro una finestra già aperta.
La falla è un out-of-bounds write in CoreGraphics. Un file costruito ad arte può far scrivere il motore grafico fuori dall’area di memoria prevista, e così far partire codice dell’attaccante quando il sistema elabora o anteprima quel contenuto. Il rischio nasce nel percorso di gestione dei contenuti: posta, chat, web e preview automatiche possono bastare.
Per gli ambienti con iPhone, iPad e Mac usati da dipendenti o utenti mobili, resta un’esposizione che passa da contenuti apparentemente ordinari e non da un accesso amministrativo o da un server esposto. La priorità ora è di contenimento: il bug è già in uso, quindi il tempo utile si misura in giorni, non in settimane.
8 fonti · 29 set
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: an out-of-bounds write issue was addressed with improved bounds checking.
Data di correzione federale CISA 2 ott
Dark Reading
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
originaleThe Register Security
Apple patches CoreGraphics zero-day already exploited in targeted attacks
Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file
originaleTechCrunch Security
Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix | TechCrunch
Apple says the bug was used to attack "specific targeted individuals" running iOS 26, which the majority of Apple customers are still using.
originalePart of the PlainSec briefing for 2026-09-29
Every edition of this story: Apple passa da zero-day a sfruttamento attivo