Skip to main content Skip to local navigation

Apple CoreGraphics Code Execution Vulnerability (CVE-2026-86950)

A recently disclosed vulnerability (CVE-2026-86950) affects Apple iOS, iPadOS, and macOS and may allow an attacker to execute arbitrary code by convincing a user to process a specially crafted file.


Severity level:
CVSS Score: 8.8/High

Description:

CVE-2026-86950 is an out-of-bounds write vulnerability in Apple's CoreGraphics framework. Processing a maliciously crafted file may trigger memory corruption and allow arbitrary code execution on an affected device. Apple has stated that it is aware of reports indicating the vulnerability may have been exploited in an extremely sophisticated attack targeting specific individuals on versions of iOS prior to iOS 27.


Affected Versions:

  • iOS versions prior to iOS 26.7.1
  • iPadOS versions prior to iPadOS 26.7.1
  • macOS Sequoia versions prior to 15.8.1
  • macOS Sequoia versions prior to 15.8.1

Impact:

Successful exploitation may allow attackers to execute arbitrary code on a vulnerable device.

Resolution:

Upgrade affected devices immediately to:

  • iOS 26.7.1 or later
  • iPadOS 26.7.1 or later
  • macOS Sequoia 15.8.1 or later
  • macOS Tahoe 26.7.1 or later

Reference:

https://www.cve.org/CVERecord?id=CVE-2026-86950

https://www.cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-971

https://nvd.nist.gov/vuln/detail/cve-2026-86950

https://support.apple.com/en-us/149226

UIT Information Security