CVE Details

CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability
Published: 2026-09-29 CVSS: 8.8 HIGH Product: Apple Multiple Products Due Date: 2026-10-02

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

No EPSS data.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 8.8
  • Severity: HIGH
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

SSVC

  • Exploitation: none
  • Automatable: no
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
dataVersion 5.2
cveMetadata > cveId CVE-2026-86950
cveMetadata > assignerOrgId 286789f9-fbc2-4510-9f9a-43facdede74c
cveMetadata > state PUBLISHED
cveMetadata > assignerShortName apple
cveMetadata > dateReserved 2026-09-08T16:43:41.881Z
cveMetadata > datePublished 2026-09-28T19:13:52.603Z
cveMetadata > dateUpdated 2026-09-29T07:15:33.456Z
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > description Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
containers > cna > affected > 0 > vendor Apple
containers > cna > affected > 0 > product iOS and iPadOS
containers > cna > affected > 0 > versions > 0 > version 0
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > lessThan 26.7.1
containers > cna > affected > 0 > versions > 0 > versionType custom
containers > cna > affected > 1 > vendor Apple
containers > cna > affected > 1 > product macOS
containers > cna > affected > 1 > versions > 0 > version 0
containers > cna > affected > 1 > versions > 0 > status affected
containers > cna > affected > 1 > versions > 0 > lessThan 15.8.1
containers > cna > affected > 1 > versions > 0 > versionType custom
containers > cna > affected > 1 > versions > 1 > version 0
containers > cna > affected > 1 > versions > 1 > status affected
containers > cna > affected > 1 > versions > 1 > lessThan 26.7.1
containers > cna > affected > 1 > versions > 1 > versionType custom
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
containers > cna > references > 0 > url https://support.apple.com/en-us/149226
containers > cna > references > 1 > url https://support.apple.com/en-us/149228
containers > cna > references > 2 > url https://support.apple.com/en-us/149229
containers > cna > providerMetadata > orgId 286789f9-fbc2-4510-9f9a-43facdede74c
containers > cna > providerMetadata > shortName apple
containers > cna > providerMetadata > dateUpdated 2026-09-28T19:13:52.603Z
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > type CWE
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > cweId CWE-787
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > lang en
containers > adp > 0 > problemTypes > 0 > descriptions > 0 > description CWE-787 Out-of-bounds Write
containers > adp > 0 > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > adp > 0 > metrics > 0 > cvssV3_1 > version 3.1
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseScore 8.8
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > adp > 0 > metrics > 0 > cvssV3_1 > baseSeverity HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
containers > adp > 0 > metrics > 0 > cvssV3_1 > integrityImpact HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > userInteraction REQUIRED
containers > adp > 0 > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > adp > 0 > metrics > 0 > cvssV3_1 > availabilityImpact HIGH
containers > adp > 0 > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > adp > 0 > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > adp > 0 > metrics > 1 > other > type ssvc
containers > adp > 0 > metrics > 1 > other > content > timestamp 2026-09-28T00:00:00+00:00
containers > adp > 0 > metrics > 1 > other > content > options > 0 > Exploitation none
containers > adp > 0 > metrics > 1 > other > content > options > 1 > Automatable no
containers > adp > 0 > metrics > 1 > other > content > options > 2 > Technical Impact total
containers > adp > 0 > metrics > 1 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 1 > other > content > version 2.0.3
containers > adp > 0 > metrics > 1 > other > content > id CVE-2026-86950
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-09-29T03:55:28.569Z
containers > adp > 1 > title CVE Program Container
containers > adp > 1 > references > 0 > url http://seclists.org/fulldisclosure/2026/Sep/89
containers > adp > 1 > references > 1 > url http://seclists.org/fulldisclosure/2026/Sep/90
containers > adp > 1 > references > 2 > url http://seclists.org/fulldisclosure/2026/Sep/91
containers > adp > 1 > providerMetadata > orgId af854a3a-2127-422b-91ae-364da2661108
containers > adp > 1 > providerMetadata > shortName CVE
containers > adp > 1 > providerMetadata > dateUpdated 2026-09-29T07:15:33.456Z