search
CVE-2026-86950
Trends
- 1Apple patches CoreGraphics flaw exploited in targeted attacks●🤖 Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics affecting older iOS/iPadOS/macOS versions. Proces
Apple has released patches for CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics affecting older versions of iOS, iPadOS and macOS. Processing a maliciously crafted file could allow arbitrary code execution. Apple says the flaw may already have been exploited in targeted attacks, prompting users of older devices to update promptly.
- 2Apple zero-day exploited in targeted attacks▼🔴 Apple CVE-2026-86950 — zero-day exploited in targeted attacks A CoreGraphics out-of-bounds write can lead to arbitrary
Apple is dealing with a newly disclosed zero-day vulnerability, CVE-2026-86950, affecting CoreGraphics on iPhone, iPad and Mac. The out-of-bounds write flaw can allow arbitrary code execution, and Apple has confirmed it was exploited in what the company describes as 'extremely sophisticated' targeted attacks. Security updates are rolling out, and users are advised to install them promptly.
- 3Apple Patches Actively Exploited Zero-Day in iOS and macOS▼Apple Patches Actively Exploited Zero-Day in iOS 26, iPadOS 26 and macOS Apple patched a zero-click vulnerability (CVE-2
Apple has released emergency security updates for iOS 26, iPadOS 26 and macOS 26 to fix a zero-click vulnerability, tracked as CVE-2026-86950, that was already being exploited in the wild. The flaw allows remote code execution and theft of user data without any interaction from the victim, and security experts are urging all iPhone, iPad and Mac users to install the patches immediately.
- 4Apple patches actively exploited CoreGraphics flaw in iOS●🤖 Apple patches CVE-2026-86950: CoreGraphics out-of-bounds write allowing code execution from a crafted file. Exploited
Apple has patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics that could allow code execution when a device processes a maliciously crafted file. The flaw was reportedly exploited in an 'extremely sophisticated' attack targeting specific individuals on iOS versions before 27. It was reported by Meta Product Security and has been added to CISA's Known Exploited Vulnerabilities catalog, with a remediation deadline of October 2.
- 5CISA adds Apple out-of-bounds write flaw to exploited vulnerabilities catalogue●CISA has added one vulnerability to the KEV catalogue: - CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vul
CISA has added CVE-2026-86950 to its Known Exploited Vulnerabilities catalogue, an out-of-bounds write vulnerability affecting multiple Apple products. Inclusion in the catalogue means the US cyber agency has evidence the flaw is being actively exploited in the wild, giving US federal agencies a deadline to patch. Security professionals are circulating the update and urging Apple users to apply fixes promptly.