SB20260928427 - Remote code execution in Apple iOS and iPadOS
Published: September 28, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-86950) Exploited
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when processing files within the CoreGraphics component. A remote attacker can trick the victim into opening a specially crated file, trigger memory corruption and execute arbitrary code on the target system.
Note, the vulnerability is being actively exploited in the wild against iPhone users.
Remediation
Install update from vendor's website.