September 30, 2026

CVE-2026-86950 - Apple CoreGraphics Out-of-Bounds Write Vulnerability

high-severity security vulnerability

Lookout Coverage and Recommendation for Admins

To ensure your devices are protected, Lookout admins should take the following steps in their Lookout console:

  • Enforce Patches: Immediately set your mobile security policy to enforce the minimum patched operating system versions iOS/iPadOS 26.7.1 (or ensure devices are upgraded to iOS/iPadOS 27 or later) across your entire Apple mobile fleet.
  • Set Policy: Set the default "OS Out of Date" policy in your management console to require the fixed versions released by Apple to address this Out-of-Bounds Write flaw.
  • Limit Access: Choose to immediately warn or block non-compliant devices from accessing work applications and data until the OS is updated. Given CISA's aggressive October 2, 2026 federal deadline, any allowed grace period should be very short and escalate in severity and limitation to the user.
  • Integrate Data: Security teams should leverage mobile EDR to integrate mobile device and app vulnerability data into their SIEM, SOAR, or XDR solution to monitor for potential exploitation attempts by sophisticated threat actors.

Overview 

CISA has listed an actively exploited zero-day vulnerability, CVE-2026-86950, in Apple's CoreGraphics framework—the core component responsible for rendering 2D vector graphics, images, and PDF documents across iOS, iPadOS, and macOS. Discovered and reported by Meta Product Security, this flaw poses an extremely high risk and has been leveraged in sophisticated, highly targeted attacks against specific individuals.

CVE-2026-86950 is an Out-of-Bounds (OOB) Write flaw. It occurs when a program writes data beyond the boundary of an allocated memory buffer when processing a maliciously crafted image or document file. An attacker can exploit this flaw by forcing the system to process a tailored file, allowing arbitrary code execution. Apple addressed this issue with improved bounds checking.

Apple is aware of reports that this issue may have been exploited in "an extremely sophisticated attack against specific targeted individuals" on versions of iOS before iOS 27. While Apple has offered no details on the exact number of targeted individuals or the timeline of initial exploitation, patches have been released across affected platforms, including iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.

CISA, on September 29, 2026, added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply the fixes by October 2, 2026. While CISA’s requirement applies strictly to Federal Civilian Executive Branch (FCEB) agencies, enterprise organizations should treat this guidance as a benchmark and mandate that employees update all corporate and personal Apple devices immediately. 

Lookout Analysis

The critical nature of this flaw is significant, as a successful exploit can achieve arbitrary code execution, which is often used to install sophisticated spyware. The exploitation of this CoreGraphics zero-day can occur through the following steps: 

  1. Preparation: A threat actor crafts a malicious file (such as an image or PDF) specifically designed to exploit the memory handling and bounds checking flaws in CoreGraphics.
  2. Delivery: The attacker directs the target device to process the malicious file. This can happen through various means, such as:
  • Delivering the file via messaging apps, email, or embedded web views within third-party applications.
  • Luring the user to visit a webpage or application where the image or document auto-renders.
  1. Exploitation: When the target device's CoreGraphics engine processes, renders, or previews the malicious file, the out-of-bounds write is triggered. This allows the attacker to execute arbitrary code within the device environment.
  2. Impact: The exploit, potentially chained with others, can be used to bypass platform protections and install powerful surveillance tools or spyware. The spyware can then collect sensitive information like messages, location data, and access the device's camera and microphone.

Authors

Abstract fan-shaped digital art with green and yellow gradient bars radiating from the center.

Lookout

Endpoint Security
Icon of a white document with lines on a dark circular background.
Entry Type
Threat Guidances
Icon of a broken smartphone with a crack on the screen.
Threat Type
Vulnerability
Black icon of an upward arrow inside a 50x50 pixel square.
Platform(s) Affected
iOS
Computer screen showing a code editor with Python code implementing a dictionary filter function.
Platform(s) Affected
Threat Guidances
Vulnerability
iOS
A woman using her phone and laptop on a train ride.Abstract white wavy lines creating a smooth flowing pattern on a light background.

Lookout Mobile Endpoint Security

Stop Cyberattacks Before They Start With Industry-Leading Threat Intelligence.

Advanced mobile Endpoint Detection & Response powered by data from 185M+ apps and 200M+ devices on iOS, Android, ChromeOS.

HeaderHeaderHeaderHeader
CellCellCellCell
CellCellCellCell
CellCellCellCell
CellCellCellCell