Apple CVE-2026-86950 Zero-Day Exploited: Update iOS, macOS Now

A Core Graphics flaw fixed in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 was used in a targeted attack. Here's what Apple says and what to do.

Apple devices displaying iOS, iPadOS, and macOS software update screens
Apple's iOS, iPadOS, and macOS software update artwork. Image: Apple.

Apple has fixed an actively exploited zero-day, CVE-2026-86950, an out-of-bounds write bug in the Core Graphics framework that can lead to arbitrary code execution when a device processes a maliciously crafted file. Apple says it is aware of a report that the flaw "may have been exploited in an extremely sophisticated attack against specific targeted individuals" running versions of iOS before iOS 27. The fix shipped on September 28, 2026 in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. If your iPhone, iPad, or Mac is not already on the current iOS 27 / iPadOS 27 / macOS Golden Gate 27 branch or on one of those four patched builds, update now.

What to know:

  • Vulnerability: CVE-2026-86950, an out-of-bounds write in Core Graphics (CWE-787)
  • Impact: Processing a maliciously crafted file can lead to arbitrary code execution
  • Status: Apple says it may have been exploited in a highly targeted attack; NVD lists active exploitation
  • Reported by: Meta's Product Security team
  • Fixed in: iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1 (September 28, 2026)
  • Not affected: Devices already running the iOS 27 / iPadOS 27 / macOS Golden Gate 27 branch, which shipped after the fix was already in place
  • CVSS score: 8.8 (High), per NVD's CVSS 3.1 assessment

What happened with CVE-2026-86950

On September 28, 2026, Apple published security advisories for iOS 26.7.1 and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1, each addressing a single vulnerability: CVE-2026-86950. According to Apple's own advisory pages, the bug is an out-of-bounds write issue in Core Graphics, the framework Apple's operating systems use to render 2D graphics and process image and document files. Apple's language across all three advisories is identical: the issue "was addressed with improved bounds checking," and "processing a maliciously crafted file may lead to arbitrary code execution."

Apple credited Meta's Product Security team with reporting the flaw, and added a line it reserves for its most serious fixes: "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals" on versions of iOS before iOS 27. That phrasing — "extremely sophisticated" and "specific targeted individuals" — is the same category of language Apple has historically used for spyware-style, mercenary-grade attacks rather than mass-market malware, though Apple's advisory does not name any attacker, spyware vendor, or victim.

Who is affected

The vulnerability sits in Core Graphics, which is shared code across Apple's platforms, so the same CVE was patched on three separate release trains at once:

  • iPhone and iPad running iOS or iPadOS versions before 26.7.1 (Apple's advisory lists iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later as in scope)
  • Mac computers on macOS Tahoe before 26.7.1
  • Mac computers on macOS Sequoia before 15.8.1

Apple's own note on active exploitation is specific to "versions of iOS before iOS 27" — in other words, the confirmed attack activity targeted iPhone and iPad users who had not yet moved to the iOS 27 branch that Apple released in mid-September. The National Vulnerability Database's technical write-up for CVE-2026-86950 lists both "iOS and iPadOS" and "macOS" as affected products, with a CVSS 3.1 base score of 8.8 (High) — network attack vector, low attack complexity, no privileges required, but user interaction required, consistent with a bug triggered by opening or processing a malicious file.

What to do right now

If you have not checked for updates in the last few days, do it now:

  1. On iPhone or iPad, go to Settings > General > Software Update and install the latest version. If your device already offers iOS 27 or iPadOS 27, updating to the latest 27.x point release is sufficient, since that branch was built and shipped after this bug was already fixed.
  2. On a Mac, go to System Settings > General > Software Update and install whatever update is offered — macOS Tahoe 26.7.1, macOS Sequoia 15.8.1, or the current macOS Golden Gate 27 branch.
  3. Turn on Automatic Updates for both "Install Security Responses and System Files" and standard OS updates, so the next fix like this one installs without waiting on you.
  4. If you are a high-risk user — a journalist, activist, government official, or anyone who believes they could be individually targeted — consider enabling Lockdown Mode (Settings > Privacy & Security > Lockdown Mode), which restricts exactly the kind of file- and message-processing attack surface this class of bug relies on.

Patched versions at a glance

PlatformFixed versionRelease dateApple advisory
iOS / iPadOS26.7.1September 28, 2026support.apple.com/en-us/149226
macOS Tahoe26.7.1September 28, 2026support.apple.com/en-us/149228
macOS Sequoia15.8.1September 28, 2026support.apple.com/en-us/149229
iOS / iPadOS / macOS Golden Gate27.0.1 branchShipped after the fix was already mergedNot separately listed as vulnerable

How to check which version you're running

Before you assume you're covered, confirm the exact build on each device:

  • iPhone or iPad: open Settings, tap General, then About. The "Software Version" or "iOS Version" line shows your current build, for example "iOS 26.7" or "iOS 27.0." If it reads anything earlier than 26.7.1 on the iOS 26 branch, or you're on iOS 27 without the .0.1 point release, go back to Software Update and install what's offered.
  • Mac: click the Apple menu, choose About This Mac, and read the macOS name and version under the Overview tab, for example "macOS Tahoe 26.7" or "macOS Sequoia 15.8." Anything below 26.7.1 on Tahoe or 15.8.1 on Sequoia needs the update.
  • iPad and iPhone eligibility: Apple's advisory ties this fix to iPhone 11 and later and to the iPad Pro, iPad Air, iPad, and iPad mini generations listed above. If your device predates that list, it's likely already outside Apple's active software-update support window for a different reason, and it's worth checking Apple's own device-support pages for what update path, if any, remains available to it.

If you are already on iOS 27, iPadOS 27, or macOS Golden Gate 27

One detail worth clarifying because it trips people up: Apple's current-generation branch — iOS 27, iPadOS 27, and macOS Golden Gate 27, which rolled out with a large feature update earlier in September — was not separately flagged as vulnerable in Apple's CVE-2026-86950 advisories. Apple's exploitation note explicitly describes the observed attack activity as targeting "versions of iOS before iOS 27," and the fix for this specific bug had already been folded into that branch before it shipped. That does not mean iOS 27 users can skip updates altogether: Apple still recommends installing the latest 27.0.1 point release, since Apple regularly bundles additional, unrelated fixes into point releases even when a specific CVE was already resolved upstream.

If your device is still on iOS 26, iPadOS 26, macOS Tahoe 26, or macOS Sequoia 15, you are on a version line that needed this patch, and 26.7.1 or 15.8.1 is the update to install.

The technical detail: an out-of-bounds write in Core Graphics

Out-of-bounds write bugs, tracked under the industry-standard weakness category CWE-787, happen when software writes data past the boundary of the memory buffer it was allocated. In a framework like Core Graphics, which parses and renders complex file formats such as images, PDFs, and fonts, a bug like this can be triggered simply by opening or previewing a file that has been deliberately malformed. Depending on how the memory corruption is exploited, an attacker can use it to escape the sandbox that's supposed to contain a rendering process and run their own code with elevated privileges on the device.

That combination — a file-parsing bug, minimal user interaction, and code execution — is exactly the profile that has been used in past mercenary spyware campaigns against journalists and activists, which is likely why Apple used its "extremely sophisticated attack against specific targeted individuals" language rather than describing broad, opportunistic exploitation. Apple's advisories do not disclose how the attack was delivered (for example, whether it required opening a message, a link, or a file), who was targeted, or which threat actor was involved; those details were not included in the published security content.

How the flaw was found and reported

Apple credits Meta's Product Security team as the reporter of CVE-2026-86950 across all three advisories. Large platform companies including Meta, Google's Threat Analysis Group, and Amnesty International's Security Lab have a track record of discovering Apple zero-days used in real-world spyware campaigns, often because the same infrastructure or malware samples show up while those teams are investigating attacks against their own users or clients. Apple does not disclose additional detail about how Meta's team identified the bug, and no separate advisory from Meta was cited in Apple's write-up.

The vulnerability is also documented in the National Vulnerability Database (NVD) as CVE-2026-86950, which assigns it a CVSS 3.1 base score of 8.8 (High) with a vector of network attack, low complexity, no privileges required, and required user interaction — and flags the exploitation status as active in the associated Stakeholder-Specific Vulnerability Categorization (SSVC) data. NVD's record lists Apple's own three advisory pages as its primary references.

Why a single CVE spans four separate updates

Apple ships one CVE across multiple simultaneous security bulletins whenever the vulnerable code is shared across its operating systems, which is common for framework-level bugs like this one in Core Graphics. That's why iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 all went out the same day, each carrying the identical fix description ("addressed with improved bounds checking") and the identical exploitation note. It's a pattern security teams have seen repeatedly this year; Pandromeda covered a similar same-day, actively exploited pattern with Cisco's ISE email gateway zero-days patched earlier this month, where a shared vulnerable component forced coordinated fixes across multiple products at once.

Protecting yourself beyond this one patch

Because this class of bug is typically delivered through a file or message rather than a phishing link you'd have to click, traditional advice like "don't click suspicious links" only goes so far. The most effective mitigations are staying current on updates, enabling Lockdown Mode if you are in a higher-risk category, and reducing your overall attack surface with strong authentication on your Apple ID — including setting up a passkey so that even if a device is compromised, your account credentials are harder to leverage elsewhere. It's also worth keeping iMessage, Mail, and messaging apps set to automatically download attachments and previews rather than manually opening files from unknown senders, and to restart your iPhone or iPad periodically — a habit that has, in past documented spyware cases, disrupted some non-persistent infections between reboots.

None of this is unique to Apple. Framework-level, file-parsing bugs like CVE-2026-86950 have shown up on every major platform, and the response is the same regardless of vendor: patch promptly, reduce your file- and message-processing attack surface if you're in a higher-risk group, and don't wait for a headline to check for updates you've been putting off.

What to do next

Check Settings > General > Software Update on every iPhone and iPad you own, and System Settings > General > Software Update on every Mac, right now. Install iOS 26.7.1 / iPadOS 26.7.1, macOS Tahoe 26.7.1, or macOS Sequoia 15.8.1 if offered, or confirm you're already on the iOS 27 / macOS Golden Gate 27 branch and grab its latest point release. Turn on automatic updates so you're not relying on catching the next advisory yourself, and if you fall into a higher-risk category, turn on Lockdown Mode today rather than waiting for the next headline.

Frequently asked questions

What is CVE-2026-86950?

CVE-2026-86950 is an out-of-bounds write vulnerability in Apple's Core Graphics framework. Apple says processing a maliciously crafted file can lead to arbitrary code execution, and the company is aware of a report that it may have been exploited in a highly targeted attack.

Which Apple devices are affected?

Apple's advisories cover iPhone 11 and later, iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later), iPad mini (5th generation and later), and Mac computers running macOS Tahoe or macOS Sequoia.

Is iOS 27 affected by CVE-2026-86950?

Apple's advisories were not issued separately for iOS 27; Apple describes the confirmed exploitation as targeting versions of iOS before iOS 27, since the fix was already included by the time the iOS 27 branch shipped. Apple still recommends installing the latest 27.0.1 point release.

How do I update my iPhone, iPad, or Mac?

On iPhone or iPad, go to Settings > General > Software Update. On a Mac, go to System Settings > General > Software Update. Install iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, or macOS Sequoia 15.8.1 if offered, or the latest available point release on iOS 27 or macOS Golden Gate 27.

Was CVE-2026-86950 actually used in attacks?

Apple says it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals. The National Vulnerability Database's record for CVE-2026-86950 also flags the exploitation status as active.

Sources

More on Apple Zero-Day →AppleiOSmacOSZero-DayCVE-2026-86950
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all