Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | CVE-2026-86950: Apple CoreGraphics Zero-Day
Sep 30, 2026
5 Mins Read
Moon
Summarize with:

CVE-2026-86950: Apple CoreGraphics Zero-Day

Apple has issued an urgent security patch for CVE-2026-86950, a critical zero-day out-of-bounds write vulnerability in CoreGraphics that enables arbitrary code execution via malicious files. Exploited in targeted, highly sophisticated attacks against specific individuals, this flaw presents an immediate threat across affected Apple platforms.

What Is CVE-2026-86950?

CVE-2026-86950 (CVSS 8.8) is an out-of-bounds write vulnerability (CWE-787) in Apple’s CoreGraphics framework, which handles graphics and related content processing across Apple operating systems.

A specially crafted file can trigger a write beyond an allocated memory boundary, potentially allowing arbitrary code execution. Apple addressed the flaw through improved bounds checking and credited Meta Product Security with its discovery.

The company has not disclosed the vulnerable function, file format, delivery mechanism, or complete exploit chain.

Details of CVE-2026-86950 (SOCRadar Free Tools, CVE Intelligence)

Details of CVE-2026-86950 (SOCRadar Free Tools, CVE Intelligence)

Which Apple Versions Are Affected?

Apple released the following security updates on September 28, 2026:

Operating System Affected Versions Fixed Version
iOS and iPadOS 26.x Before 26.7.1 26.7.1
macOS Tahoe 26.x Before 26.7.1 26.7.1
macOS Sequoia 15.x Before 15.8.1 15.8.1

Apple details the fixes in its advisories for iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.

Apple’s exploitation warning specifically mentions targeted individuals running iOS versions before iOS 27. This does not establish that the flaw was exploited across every affected operating system or fully clarify the security status of iOS 27.

Administrators should verify device compatibility and installed versions using Apple’s current guidance and their endpoint inventory.

How Could CVE-2026-86950 Be Exploited?

Exploitation requires a vulnerable Apple component to process a maliciously crafted file, triggering memory corruption that could lead to code execution.

Because CoreGraphics is a shared framework, multiple applications may invoke its functionality. However, Apple has not identified the processing path used in the reported attacks.

There is also no public confirmation that CVE-2026-86950 independently provides kernel-level execution, sandbox escape, privilege escalation, or persistence. The available disclosure does not establish whether the attacks involved zero-click or one-click delivery.

Is CVE-2026-86950 Being Exploited in the Wild?

Apple has acknowledged a report of possible exploitation in a sophisticated, targeted attack.

According to its September 28 advisories, the vulnerability may have been used against specific individuals running versions of iOS before iOS 27.

On September 29, CISA added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog, assigning an October 2, 2026 remediation deadline for covered federal agencies.

Several details remain undisclosed, including:

  • The responsible threat actor or spyware family.
  • The malicious file format and delivery channel.
  • The number of affected individuals.
  • Whether the same exploit targeted iPadOS or macOS.
  • The complete post-exploitation capabilities.

Meta Product Security is credited with reporting the flaw, not with attribution of the attacks.

Current evidence points to targeted exploitation rather than a publicly documented mass-exploitation campaign.

Track CVE-2026-86950 with SOCRadar

With CVE-2026-86950 now included in CISA’s KEV catalog, organizations should monitor exploitation developments alongside Apple endpoint patching.

SOCRadar’s Cyber Threat Intelligence (CTI) module can help teams follow advisory updates, exploitation status, and emerging technical information. Combined with mobile device management (MDM) and endpoint inventory data, this intelligence can support remediation prioritization, particularly for devices assigned to high-risk users.

SOCRadar’s Vulnerability Intelligence, CTI module

SOCRadar’s Vulnerability Intelligence, CTI module

What Should Defenders Do?

Apply Apple’s Security Updates

Deploy the applicable fixed release:

  • iOS and iPadOS: 26.7.1 or a later applicable fixed release.
  • macOS Tahoe: 26.7.1 or later.
  • macOS Sequoia: 15.8.1 or later.

Use MDM and endpoint management tools to identify vulnerable devices, deploy updates, and verify installation.

Prioritize devices belonging to individuals who may face sophisticated surveillance threats, including executives, journalists, activists, and personnel handling sensitive information.

Reduce Risk if Patching Is Delayed

Until updates are deployed, limit unnecessary handling of untrusted files and apply stricter access controls to unmanaged or noncompliant devices.

Apple’s Lockdown Mode may offer additional protection for high-risk individuals, although it has not been established as a complete mitigation for CVE-2026-86950.

Disabling a single application also cannot be assumed to eliminate exposure because the vulnerable CoreGraphics processing path remains undisclosed.

Hunt for Suspicious Activity

Apple has not published CVE-specific indicators of compromise, malicious file hashes, or reliable detection signatures.

Defenders can nevertheless review available endpoint and diagnostic telemetry for:

  • Unexplained crashes involving applications that process graphics, documents, or other files.
  • Suspicious file-processing events preceding abnormal application behavior.
  • Unexpected process execution or system changes on vulnerable Macs.
  • Unusual activity on devices belonging to high-risk users.
  • Crash reports and diagnostic artifacts associated with suspicious content.

These are general hunting opportunities, not confirmed indicators of CVE-2026-86950 exploitation. A CoreGraphics-related crash alone does not establish compromise.

Preserve Evidence if Compromise Is Suspected

Where targeted compromise is suspected, preserve available crash logs, diagnostic records, endpoint telemetry, and suspicious files before disruptive changes, when operationally appropriate.

Investigators should assess surrounding activity rather than assume exploitation automatically resulted in persistence, privilege escalation, or data theft.

For enterprise environments, patching should be paired with an assessment of devices that remained vulnerable before the security updates were installed.