Full Report
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the
Analysis Summary
# Vulnerability: Apple CoreGraphics Out-of-Bounds Write
## CVE Details
- **CVE ID:** CVE-2026-86950
- **CVSS Score:** Not explicitly listed (Estimated High based on "Arbitrary Code Execution" impact)
- **CWE:** CWE-787 (Out-of-bounds Write)
## Affected Systems
- **Products:** iOS, iPadOS, macOS Tahoe, macOS Sequoia.
- **Versions:**
- iOS and iPadOS versions prior to 26.7.1
- macOS Tahoe versions prior to 26.7.1
- macOS Sequoia versions prior to 15.8.1
- **Configurations:** Systems processing maliciously crafted files (e.g., images or PDFs) handled by the CoreGraphics framework.
## Vulnerability Description
CVE-2026-86950 is an out-of-bounds write vulnerability within the **CoreGraphics** component. The flaw stems from insufficient bounds checking when processing a specially crafted file. An attacker can leverage this memory corruption to bypass security boundaries and execute arbitrary code in the context of the application or the OS.
## Exploitation
- **Status:** Exploited in the wild (Reported by Apple as possibly exploited in "extremely sophisticated" targeted attacks).
- **Complexity:** High (Associated with targeted attacks against specific individuals).
- **Attack Vector:** Local/Network (Triggered via the processing of a malicious file, often delivered via web, email, or messaging).
## Impact
- **Confidentiality:** High (Potential for full data access via code execution).
- **Integrity:** High (Unauthorized system modifications possible).
- **Availability:** High (Potential for system crashes or persistent compromise).
## Remediation
### Patches
Apple has released the following updates to address the issue:
- **iOS 26.7.1 and iPadOS 26.7.1:** For iPhone 11 and later, and various iPad models (Pro 3rd gen+, Air 3rd gen+, Mini 5th gen+).
- **macOS Tahoe 26.7.1:** For systems running macOS Tahoe.
- **macOS Sequoia 15.8.1:** For systems running macOS Sequoia.
### Workarounds
- No official functional workarounds are available. Users are advised to update to the latest OS versions immediately.
- Exercise caution when opening files from unknown or untrusted sources.
## Detection
- **Indicators of Compromise:** Unusual crashes in applications that utilize CoreGraphics (e.g., Preview, Safari, Mail).
- **Detection Methods:** Vulnerability scanners should check for OS build numbers corresponding to the patched versions listed above. Security teams should monitor for exploit attempts involving sophisticated, targeted delivery of media files.
## References
- **Vendor Advisory (iOS/iPadOS):** hxxps://support[.]apple[.]com/en-us/149226
- **Vendor Advisory (macOS Tahoe):** hxxps://support[.]apple[.]com/en-us/149228
- **Vendor Advisory (macOS Sequoia):** hxxps://support[.]apple[.]com/en-us/149229
- **Source Article:** hxxps://thehackernews[.]com/2026/09/apple-patches-coregraphics-flaw[.]html