What is CVE-2026-86950?
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Timeline
- 2026-09-28Published to the U.S. National Vulnerability Database (NVD)
- 2026-09-29First covered in a defend.network daily briefing
- 2026-09-29NVD record last updated
Affected product
See advisory
Remediation Steps
- Apply Apple security updates to affected iOS, iPadOS, and macOS devices
- Prioritize devices in high-risk environments (government, finance)
- Avoid opening untrusted files that could exploit the out-of-bounds write
- Monitor for suspicious file processing or unexpected code execution
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 4 of September 2026 (September 28 – October 4)
- Apple zero-day, Microsoft mega-patch (974 CVEs), ShinyHunters Oracle escalation (2026-09-29)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.