Apple iOS, iPadOS and macOS CoreGraphics Out-of-Bounds Write Vulnerability
Release Date: 29th September 2026 (Added 6th October 2026)
Impact : CRITICAL
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2026-86950 is an out-of-bounds write vulnerability (CWE-787) in the CoreGraphics framework used by Apple iOS, iPadOS and macOS. Processing a maliciously crafted file may lead to arbitrary code execution on the device. The flaw was reported by Meta Product Security.
What are the systems affected?
The following Apple operating systems are affected prior to the fixed releases:
iOS and iPadOS 26.x, before 26.7.1 – (Affected)
macOS Tahoe 26.x, before 26.7.1 – (Affected)
macOS Sequoia 15.x, before 15.8.1 – (Affected)
Not affected / patched version:
iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 or later – (Not affected)
What does this mean?
Successful exploitation may allow attackers to:
- Execute arbitrary code on a device by getting the user to open or process a maliciously crafted file
- Compromise the confidentiality, integrity and availability of the device and the data it holds
- Be used in highly targeted attacks against individuals such as officials, journalists and other high-risk users
Mitigation process?
CERTVU recommends the following:
-
Update All Apple Devices Immediately
Install iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1 on all managed and personal devices used for work, and enable automatic updates. -
Prioritize High-Risk Users
-
Be Cautious with Unsolicited Files
-
Enforce Updates Through Device Management
Reference
- https://support.apple.com/en-us/100100
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://nvd.nist.gov/vuln/detail/CVE-2026-86950
- Download advisory (English): Apple iOS, iPadOS and macOS CoreGraphics Out-of-Bounds Write Vulnerability