CVE-2026-86950: High severity Apple iOS vulnerability
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Other sources
CoreGraphics. An out-of-bounds write issue was addressed with improved bounds checking.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.7.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.8.1 - Upgrade
Upgrade
iOSto a version that resolves this vulnerability.Fixed in 26.7.1 - Upgrade
Upgrade
iPadOSto a version that resolves this vulnerability.Fixed in 26.7.1 - Upgrade
Upgrade
macOS Sequoiato a version that resolves this vulnerability.Fixed in 15.8.1 - Upgrade
Upgrade
macOS Tahoeto a version that resolves this vulnerability.Fixed in 26.7.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
Which product families should be included in remediation planning?
The affected software list includes Apple iOS, Apple iPadOS, macOS Sequoia, and macOS Tahoe.