Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks

Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) (TL-2026-2745) is a high-severity software vulnerability scored CVSS 8.8, first published 2026-09-28 and last reviewed 2026-09-29. It has no confirmed attribution, affects Apple iOS and iPadOS, references 1 CVE (CVE-2026-86950), maps to 8 MITRE ATT&CK techniques (T1203, T1204.002, T1587.004), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-2745

Threat ID
TL-2026-2745
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-09-28
Last reviewed
2026-09-29
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
targeted-individuals
Detection rules
9
Indicators of compromise
17
Updates
2026-09-29 · 3 updates · revalidated 3× · latest source

Apple patched CVE-2026-86950, an out-of-bounds write in the CoreGraphics framework that can lead to arbitrary code execution when a maliciously crafted file is processed. Apple says it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27; Meta Product Security reported it.

How Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) works

CVE-2026-86950 is an out-of-bounds write (CWE-787) in CoreGraphics, Apple's core 2D drawing and rendering framework. All three Apple advisories describe the impact as: processing a maliciously crafted file may lead to arbitrary code execution. The fix is described as 'improved bounds checking'. The flaw is fixed in iOS 26.7.1 and iPadOS 26.7.1 (iPhone 11 and later; iPad Pro 12.9-inch 3rd generation and later; iPad Pro 11-inch 1st generation and later; iPad Air 3rd generation and later; iPad 8th generation and later; iPad mini 5th generation and later), macOS Tahoe 26.7.1 (build 25G241 per 9to5Mac) and macOS Sequoia 15.8.1 (build 24H32 per 9to5Mac). The advisories (support.apple.com 149226, 149228, 149229) were released on 2026-09-28, each contains only this single CVE, and each credits Meta Product Security.

Exploitation status: Apple states it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. This is a possible-exploitation statement, not a confirmed in-the-wild campaign. Apple published no details on how many people were targeted, whether any attempt succeeded, when exploitation began, the delivery vector, the file format, or the threat actor. The exploitation wording appears only in Apple's text; the advisories for macOS Tahoe and macOS Sequoia repeat the same sentence but name iOS as the exploited platform, so no macOS exploitation is stated. The NVD record (CNA: product-security@apple.com, status 'Received') carries a CISA-ADP SSVC v2.0.3 assessment of Exploitation: None, Automatable: No, Technical Impact: Total, so the exploitation claim rests on Apple's vendor statement alone. The CVE was reserved on 2026-09-08 (per Strix and OffSeq aggregator data) and published in NVD on 2026-09-28 at 20:17 UTC. It is not listed in the CISA KEV catalog: the KEV JSON re-retrieved during this research pass is still catalog version 2026.09.27 (1,728 entries, released 2026-09-27), which predates the disclosure, so absence from KEV is expected and should be re-checked; Strix also reports no KEV listing. No public proof-of-concept was found in any source or search, and searches for Citizen Lab, Amnesty, Google TAG or Lookout involvement returned nothing: the only credited reporter is Meta Product Security.

Severity: the NVD record scores it CVSS 3.1 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; exploitability 2.8, impact 5.9). The vector implies network delivery of a file and user interaction; Apple states only that the file is 'processed', so a delivery path that needs no explicit user action cannot be ruled out from public information. Scope is Unchanged, and Apple describes code execution only; no sandbox escape or privilege escalation is stated. OffSeq's phrase 'full device compromise' is aggregator characterization, not Apple text.

OS branch context: iOS 27 shipped on 2026-09-14 (per AppleMagazine), the same day as Apple's large September update wave (iOS/iPadOS 27 and 26.7, macOS 27 Golden Gate, macOS Tahoe 26.7, macOS Sequoia 15.8, tvOS/watchOS/visionOS 27, Safari 27, Xcode 27; 273 CVEs per the Zero Day Initiative review, which also notes several crafted-file image-parsing fixes such as ImageIO CVE-2026-65346 and a separately CISA-confirmed exploited Screen Sharing Server flaw, CVE-2026-65400; neither is linked to CVE-2026-86950 by any source). iOS 27.0.1, iPadOS 27.0.1 and macOS Golden Gate 27.0.1 (build 26A5434 per 9to5Mac) were released the same day as the 26.7.1 updates and Apple's advisories for them carry no published CVE entries, so CVE-2026-86950 is not listed as fixed in them (MacRumors, AppleMagazine, 9to5Mac). Apple's phrase 'versions of iOS before iOS 27' therefore bounds the reported exploitation, but the advisories do not say whether iOS 27.0 itself was vulnerable; the only fixed builds Apple lists are the 26.x ones. MacRumors, 9to5Mac and AppleMagazine infer the iOS 27 branch already carries the fix; that is press inference, not an Apple statement. Reporting is inconsistent on the boundary: AppleMagazine frames exposure as 'versions older than iOS 26.7.1', MacRumors as 'iOS 26 and earlier', Apple's wording is 'before iOS 27', and TidBITS states iOS/iPadOS before 27.0 are patched in 27.0.1, which conflicts with Apple's own 27.0.1 advisories listing no CVEs.

Source discrepancies: TheHackerWire titles the record 'OS Command Injection' while quoting the official out-of-bounds-write description and CWE-787; the vendor and NVD data are authoritative and this record follows CWE-787. Strix and OffSeq list iOS/iPadOS as the affected product with macOS Sequoia and Tahoe as additional affected products (matching NVD ranges: iOS/iPadOS < 26.7.1, Tahoe < 26.7.1, Sequoia < 15.8.1). TidBITS links to Pegasus as an example of spyware but cites no evidence that the flaw is used in it; no other source repeats this and it is NOT treated as attribution here.

Intelligence gaps: no malware family, implant, C2 infrastructure, file hashes, file format, or attribution has been published, so no BeaconBeagle pivot is possible (there are no network IOCs to query). The IOC list therefore contains only vulnerability, component, device, and version/build artifacts useful for exposure and patch-compliance hunting, not adversary infrastructure. The MITRE mapping is limited to what follows from stated facts: exploitation of a client-side flaw for initial access and code execution (mobile T1664/T1658 and the enterprise T1203 for the macOS builds), a crafted file that must be processed/opened (T1204.002), possession of an exploit and vulnerability knowledge for a pre-patch attack (T1587.004, T1588.005, T1588.006; Apple does not say whether the exploit was developed or acquired, so both are listed), and selection of specific individuals (T1589, inferred from the 'specific targeted individuals' wording). Apple did not disclose the delivery vector or any post-exploitation behavior, so no phishing, drive-by, sandbox-escape, privilege-escalation, persistence, collection or exfiltration techniques are mapped; adding them would be invention. Apple's exploitation wording matches its earlier disclosure for the dyld flaw CVE-2026-20700 (patched 2026-02-11/12 in iOS 26.3 and companion releases, reported by Google TAG, exploited in an extremely sophisticated attack against targeted individuals on iOS before iOS 26; Apple noted it was related to WebKit CVE-2025-43529 and Chrome ANGLE CVE-2025-14174 patched in December 2025), but no source links the two issues and no source says CVE-2026-86950 was part of an exploit chain.

Component precedent (context only): CoreGraphics (the Quartz graphics layer) was also the component in FORCEDENTRY (CVE-2021-30860, September 2021, found by Citizen Lab, attributed to NSO Group's Pegasus), where a PDF disguised as a GIF carrying JBIG2 data triggered an integer overflow delivered via iMessage. No source ties CVE-2026-86950 to that exploit, its file format, its delivery channel or its vendor; it is recorded only so defenders know that crafted-file parsing in CoreGraphics has previously been a spyware entry point. MacRumors characterizes the exploitation as targeting 'a small number of people' and not widespread, and warns that public disclosure raises the risk of copycat exploitation; Apple itself gives no such figures. The VulDB record for this CVE (vuldb.com/vuln/411158) appears in search results but returned HTTP 403 and could not be read. For the earlier CVE-2026-20700 disclosure, Malwarebytes describes an infection chain with CVE-2025-14174 and CVE-2025-43529 and recommends Apple Lockdown Mode for high-value targets; no source makes that recommendation for CVE-2026-86950 specifically.

MITRE mapping scope: eight techniques are mapped and each rests on a stated fact (client-side flaw exploited via a crafted file, targeting of specific individuals, exploit possession). Delivery-vector techniques (Phishing T1566/T1660, Drive-by Compromise T1189, Malicious Image T1204.003) and any post-exploitation technique were deliberately left out because Apple did not disclose the delivery vector, file format or post-exploitation behavior.

MITRE ATT&CK techniques used in TL-2026-2745

Execution

T1203 Exploitation for Client Execution; T1204.002 Malicious File; T1658 Exploitation for Client Execution

Resource Development

T1587.004 Exploits; T1588.005 Exploits; T1588.006 Vulnerabilities

Reconnaissance

T1589 Gather Victim Identity Information

Initial Access

T1664 Exploitation for Initial Access

Affected products and versions in Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950)

  • Apple — iOS and iPadOS
    Vulnerable versions: Versions before 26.7.1
    Fixed in: 26.7.1
  • Apple — macOS Tahoe
    Vulnerable versions: Versions before 26.7.1
    Fixed in: 26.7.1 (build 25G241)
  • Apple — macOS Sequoia
    Vulnerable versions: Versions before 15.8.1
    Fixed in: 15.8.1 (build 24H32)

Remediation for Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950)

Patches

  • iOS 26.7.1 and iPadOS 26.7.1 (Apple HT 149226)
  • macOS Tahoe 26.7.1 (Apple HT 149228)
  • macOS Sequoia 15.8.1 (Apple HT 149229)

Immediate actions

  • Update iPhones and iPads to iOS 26.7.1 / iPadOS 26.7.1 (or to iOS 27.0.1 / iPadOS 27.0.1) and Macs to macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1
  • Prioritize patching for individuals at elevated risk of targeted attacks (executives, journalists, government and civil-society staff)
  • Use MDM compliance reporting to find devices below the fixed OS builds (Tahoe 25G241, Sequoia 24H32)
  • Note that Apple's iOS 27.0.1 advisory lists no CVEs; devices on iOS 27.0 should still move to 27.0.1 but the fix status of the 27 branch is not stated by Apple

Workarounds

  • No vendor workaround published; the fix is the OS update

Longer-term hardening

  • Enforce minimum OS version policies and automatic updates on managed Apple devices
  • Consider Apple Lockdown Mode for individuals at high risk of targeted attacks
  • Treat files from untrusted senders as hostile on mobile endpoints
  • Re-check the CISA KEV catalog for a CVE-2026-86950 listing after the 2026-09-27 catalog snapshot

CVEs associated with Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950)

CVE-2026-86950

Weaknesses (CWE) in Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950)

CWE-787

Timeline of Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950)

  • Context only: Apple patches FORCEDENTRY (CVE-2021-30860), a CoreGraphics integer overflow found by Citizen Lab and attributed to NSO Group's Pegasus (crafted PDF/JBIG2 delivered via iMessage); no source links it to CVE-2026-86950 (exact disclosure day approximate, September 2021)
  • Context only: Apple disclosed dyld flaw CVE-2026-20700 (reported by Google TAG, fixed in iOS 26.3 and companion releases) as possibly exploited in an extremely sophisticated attack against targeted individuals on iOS before iOS 26, related to December 2025 WebKit CVE-2025-43529 and ANGLE CVE-2025-14174; no source links it to CVE-2026-86950
  • CVE-2026-86950 identifier reserved (per CVE record data aggregated by Strix and OffSeq)
  • Apple ships its September 2026 update wave (iOS/iPadOS 27 and 26.7, macOS 27 Golden Gate, macOS Tahoe 26.7, macOS Sequoia 15.8 and others; 273 CVEs per the Zero Day Initiative review). The later CoreGraphics fix ships as the 26.7.1 point release on top of this wave; no source links CVE-2026-86950 to any CVE in it
  • Apple releases iOS 27; Apple's later exploitation statement is scoped to iOS versions before iOS 27 (release date per AppleMagazine)
  • CISA KEV catalog v2026.09.27 (1,728 entries) is the latest snapshot retrievable during research (checked twice); it predates the disclosure and contains no CVE-2026-86950 entry
  • SANS ISC (Johannes Ullrich) publishes a diary on the emergency patch stating iOS 27 and macOS 27 are not affected by CVE-2026-86950, closing the ambiguity Apple's bulletins left about whether the 27 branch ever contained the flaw, and notes iOS 27.1 is expected next (reportedly to add foldable-iPhone support).
  • TidBITS links to Pegasus as an example of spyware without cited evidence that this flaw is used in it; no other source repeats this and it is not accepted as attribution
  • The Hacker News, MacRumors, AppleMagazine, 9to5Mac, TidBITS, GuardianMSSP and other outlets report the patch and Apple's possible-exploitation statement; no public proof-of-concept, delivery vector or actor attribution identified
  • CVE-2026-86950 published in NVD (20:17 UTC, status Received) with CWE-787 and CVSS 3.1 base score 8.8; CISA-ADP SSVC lists Exploitation: None, Automatable: No, Technical Impact: Total
  • iOS 27.0.1, iPadOS 27.0.1 and macOS Golden Gate 27.0.1 (build 26A5434) ship the same day with no published CVE entries, so CVE-2026-86950 is not listed for them (MacRumors, AppleMagazine, 9to5Mac); whether iOS 27.0 was affected is not stated by Apple
  • Apple states it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27; exploitation start date, victims, delivery vector and actor are undisclosed
  • Apple releases iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 (build 25G241) and macOS Sequoia 15.8.1 (build 24H32) fixing the CoreGraphics out-of-bounds write with improved bounds checking; credit to Meta Product Security
  • CISA adds CVE-2026-86950 to the Known Exploited Vulnerabilities catalog with a federal remediation due date of 2026-10-02, superseding the earlier v2026.09.27 snapshot that predated disclosure.
  • CISA KEV remediation due date for CVE-2026-86950 (federal agencies); the KEV entry references BOD 26-04 guidance and forensics triage requirements.

Update history for TL-2026-2745

Sources cited for Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950)

More in vulnerability

Detection coverage for TL-2026-2745

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2745 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats