A recently disclosed vulnerability (CVE-2026-86950) affects Apple iOS, iPadOS, and macOS and may allow an attacker to execute arbitrary code by convincing a user to process a specially crafted file.
Severity level:
CVSS Score: 8.8/High
Description:
CVE-2026-86950 is an out-of-bounds write vulnerability in Apple's CoreGraphics framework. Processing a maliciously crafted file may trigger memory corruption and allow arbitrary code execution on an affected device. Apple has stated that it is aware of reports indicating the vulnerability may have been exploited in an extremely sophisticated attack targeting specific individuals on versions of iOS prior to iOS 27.
Affected Versions:
- iOS versions prior to iOS 26.7.1
- iPadOS versions prior to iPadOS 26.7.1
- macOS Sequoia versions prior to 15.8.1
- macOS Sequoia versions prior to 15.8.1
Impact:
Successful exploitation may allow attackers to execute arbitrary code on a vulnerable device.
Resolution:
Upgrade affected devices immediately to:
- iOS 26.7.1 or later
- iPadOS 26.7.1 or later
- macOS Sequoia 15.8.1 or later
- macOS Tahoe 26.7.1 or later
Reference:
https://www.cve.org/CVERecord?id=CVE-2026-86950
https://www.cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-971
https://nvd.nist.gov/vuln/detail/cve-2026-86950
https://support.apple.com/en-us/149226
UIT Information Security
