Out-of-Bounds Write Vulnerability in Apple's iOS, iPadOS, and macOS
CVE-2026-86950

8.8HIGH

Key Information:

Vendor

Apple

Vendor
CVE Published:
28 September 2026

Badges

📰 News Worthy

What is CVE-2026-86950?

An out-of-bounds write vulnerability has been identified in Apple's operating systems, potentially allowing attackers to execute arbitrary code through specially crafted files. Affected systems include earlier versions of iOS, iPadOS, and specific macOS versions. Apple has implemented improved bounds checking to mitigate this issue, but users are advised to update to the latest software versions to ensure protection against possible exploitation, particularly as reports indicate that this vulnerability may have been used in highly targeted attacks.

Affected Version(s)

iOS and iPadOS 0 < 26.7.1

macOS 0 < 15.8.1

macOS 0 < 26.7.1

News Articles

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Apple patched CVE-2026-86950, a CoreGraphics flaw that may have been exploited in targeted attacks via maliciously crafted

3 hours ago

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

.