Out-of-bounds write in Apple iOS and iPadOS - CVE-2026-86950

 

Out-of-bounds write in Apple iOS and iPadOS - CVE-2026-86950

Published: September 28, 2026


Vulnerability identifier: #VU152689
CSH Severity: Critical
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-86950
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing files within the CoreGraphics component. A remote attacker can trick the victim into opening a specially crated file, trigger memory corruption and execute arbitrary code on the target system.

Note, the vulnerability is being actively exploited in the wild against iPhone users. 


Affected software

Apple iOS
iPadOS
macOS

How to mitigate CVE-2026-86950

Install updates from vendor's website.

Apple iOS - update to 26.7.1 23H30
iPadOS - update to 26.7.1 23H30
macOS - addressed in versions 15.8.1 24H32, 26.7.1 25G241

External References

Related Security Bulletins