Apple’s CVE-2026-86950 is a bug in CoreGraphics, the low-level Apple framework that applications and the operating system use to draw and process images, PDFs, masks, colour data and other two-dimensional graphics. It is not a service an administrator installs or exposes deliberately: it is part of iOS, iPadOS and macOS, so the practical population is the fleet of Apple endpoints running those operating systems.
The issue is an out-of-bounds write. In plain terms, while CoreGraphics processes specially formed file data, it can write beyond the memory area allocated for it. That can corrupt nearby memory and, in the stated impact, let an attacker run code. Apple says processing a maliciously crafted file may lead to arbitrary code execution, but does not disclose the file format, the vulnerable function, the malformed field or the delivery route. There is no published source-level patch or reliable code pattern to inspect.
A file is the attacker’s entry point
The CVSS vector assigns no privileges but does require user interaction. That is consistent with a victim having to open, preview or otherwise cause software to process the attacker’s file; it does not establish which app handles it or exactly what action triggers the flaw. Nor has Apple identified an attacker, victim group, spyware vendor, delivery application, indicators of compromise or a complete exploit chain.
Apple’s wording matters here: it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals using versions of iOS before iOS 27. That is evidence of possible in-the-wild use, not a public account of a broad campaign. Meta Product Security reported the bug, but no public technical report explaining the discovery is available.
CISA nevertheless added CVE-2026-86950 to its Known Exploited Vulnerabilities catalogue on September 29, 2026, with an October 2 deadline for US federal civilian agencies. The catalogue records ransomware use as unknown. A GitHub repository branded as a PoC contains a README and a paid-download pointer, but no source or malicious sample; no publicly reviewable proof of concept or exploit code has surfaced.
Update the operating system, not an app
Apple released fixes on September 28, 2026: iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. The iPhone and iPad update covers supported iPhone 11-and-later and listed supported iPad generations. Apple’s advisories do not publish formal affected-version ranges, and they do not explicitly say iOS/iPadOS 27 or macOS Golden Gate 27 are unaffected. They also offer no workaround short of installing the operating-system update.
For IT teams, this is endpoint hygiene with a sharper reason to move quickly: inventory managed iPhones, iPads and Macs; deploy the applicable update; and chase devices that are offline, personally owned or outside management. Businesses of every size, schools and school districts all commonly run these platforms, and an organization need not use a special Apple graphics product to be exposed.
Treat the patch as a priority even if no suspicious file has been found. SecAlerts monitors an organisation's actual software stack and alerts on new vulnerabilities affecting the products it runs; here, that inventory should include the operating-system versions across the Apple fleet.




