Apple iOS, iPadOS and macOS CoreGraphics Out-of-Bounds Write Vulnerability

Release Date: 29th September 2026 (Added 6th October 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-86950 is an out-of-bounds write vulnerability (CWE-787) in the CoreGraphics framework used by Apple iOS, iPadOS and macOS. Processing a maliciously crafted file may lead to arbitrary code execution on the device. The flaw was reported by Meta Product Security.

Reference

  1. https://support.apple.com/en-us/100100
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  3. https://nvd.nist.gov/vuln/detail/CVE-2026-86950