Vulnerability  ·  2026-09-30

Apple CoreGraphics OOB write (CVE-2026-86950) — KEV, exploited in targeted attacks on iOS/macOS

VulnerabilityHigh impactGlobalCVE-2026-86950
CISA added CVE-2026-86950 to the KEV catalog on 2026-09-29 with confirmed in-the-wild exploitation; Apple patched it 2026-09-28 in iOS/iPadOS 26.7.1 and macOS Tahoe 26.7.1/Sequoia (CoreGraphics, out-of-bounds write, CWE-787). Federal due date 2026-10-02 per BOD 26-04. Reported to Apple by Meta Product Security.
This is a KEV-class actively-exploited memory-corruption bug on the platforms that host Apple's on-device AI (Apple Intelligence), local LLM tooling, and AI developer machines. A malicious file is the delivery vehicle and it yields code execution — on a macOS developer/AI workstation that is a direct path into local model data, repo secrets, and agent credentials. It is not AI-specific, but it is confirmed in-the-wild exploitation on the very platforms the AI fleet runs on.
Processing a maliciously crafted file (e.g. image/PDF reaching CoreGraphics) causes an out-of-bounds write leading to arbitrary code execution; Apple confirms it was exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 27.
Apple iOS, macOS (Tahoe), iPadOS — iOS 26.7.1/iPadOS 26.7.1, macOS Tahoe 26.7.1 / Sequoia; also fixed for iPhone 11 and later, iPad 3rd-gen+ and relevant macOS releases (support.apple.com/en-us/149226, /149228, /149229)
Apply Apple updates for iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 / Sequoia immediately per CISA KEV (BOD 26-04); treat unsolicited files on AI/dev machines as hostile until patched.
Apple security content iOS 26.7.1Apple macOS security contentCISA KEV catalog
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →