ZeroDayAlert

CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

Apple Multiple Products Added to KEV 2026-09-29 Federal due 2026-10-02 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

This vulnerability affects Apple's iOS, macOS, and iPadOS operating systems. The flaw exists in the CoreGraphics framework, which handles graphics rendering across these platforms. The record does not specify particular versions, device models, or whether the vulnerability affects enterprise-specific deployments differently.

How to check whether this touches you

  • Inventory step: List all Apple devices in your infrastructure: iPhones, iPads, Mac laptops, Mac minis, or other devices running iOS, macOS, or iPadOS.
  • Reachability: Determine whether each device connects to untrusted networks or processes untrusted graphic content (downloaded files, web browsing, email attachments). Devices isolated to internal networks only carry lower immediate risk.
  • Version confirmation: Check Settings > General > About on iOS/iPadOS or System Settings > General > About on macOS to record the current OS version. Note that Apple backports security fixes, so version alone is not a complete signal of patch status.
  • Graphics load testing: Identify applications or workflows that render complex or user-supplied graphics, as these increase exploitation surface.

What to do

  1. Immediate prioritisation: Categorise devices by exposure and criticality. Internet-facing or frequently-used devices handling external graphics should be prioritised under BOD 26-04 guidelines.
  2. Obtain patched versions: Contact Apple or consult official security advisories to identify the patched OS versions for your affected products. Apply these updates according to your change management process, beginning with high-exposure devices.
  3. Interim containment (if patching is delayed): Restrict untrusted graphic file downloads and disable graphics-heavy web features where operationally feasible. Consider network segmentation to limit lateral movement if exploitation occurs.
  4. Logging: Enable OS-level security logging (unified log on macOS, Settings > Privacy on iOS) to capture crashes, memory access violations, or unusual process behaviour that may indicate exploitation attempts.
  5. Escalation criteria: If a device cannot be patched within your organisation's BOD 26-04 deadline and remains internet-connected, escalate to your risk and compliance teams to determine whether continued use is acceptable or the device must be discontinued.

If you find you were exposed

Out-of-bounds write flaws in graphics libraries are typically exploited through malicious files or crafted content, which may have been delivered days or weeks before discovery. Audit your logs for suspicious process terminations, memory faults, or unexpected application behaviour in the CoreGraphics timeframe. Review email gateways and web proxies for graphic file downloads from untrusted sources during the period the device was unpatched. Retention of crash dumps, system logs, and network traffic for at least 90 days will be essential for forensic triage.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-86950 is being exploited. It cannot tell you whether Multiple Products is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →