Apple CoreGraphics file OOB write hits CISA KEV
How to fix CVE-2026-86950: update to iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1
Contents
CISA added CVE-2026-86950 to the Known Exploited Vulnerabilities catalog today (2026-09-29). Apple CoreGraphics has an out-of-bounds write: processing a maliciously crafted file may lead to arbitrary code execution on iPhone, iPad, and Mac. Apple published fixes yesterday (2026-09-28) in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1. Apple also says it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. Credit goes to Meta Product Security. Federal KEV due date is 2026-10-02. Forensic triage is Yes under BOD 26-04. Known ransomware campaign use is Unknown.
This page is the operator write-up from Apple's three security content notes, CISA KEV catalogVersion 2026.09.29, and NVD. The HOL Guard evidence pack for CVE-2026-86950 is the linked source record (title may still read the ADP stub until editorial lands).
What breaks
CoreGraphics is the system graphics stack that opens images and related files across Apple platforms. An out-of-bounds write (CWE-787) in that path means a crafted file the device processes can corrupt memory and, in Apple's words, lead to arbitrary code execution. Apple addressed it with improved bounds checking. The same CVE row appears on all three patch trains:
- iOS 26.7.1 and iPadOS 26.7.1 (released 2026-09-28). Available for iPhone 11 and later; iPad Pro 12.9-inch 3rd generation and later; iPad Pro 11-inch 1st generation and later; iPad Air 3rd generation and later; iPad 8th generation and later; iPad mini 5th generation and later.
- macOS Tahoe 26.7.1 (released 2026-09-28). Available for macOS Tahoe.
- macOS Sequoia 15.8.1 (released 2026-09-28). Available for macOS Sequoia.
Apple's impact text on each advisory is identical, including the targeted-individuals exploitation acknowledgment for older iOS trains before iOS 27.
Who is not in scope
- Devices already on the fixed builds: iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1 (or newer on that train).
- Hardware Apple does not list for these updates: for example iPhone models older than iPhone 11, and iPads outside the generations named in the iOS/iPadOS note. Those devices do not get this patch train; track Apple's product support pages for what still receives security updates.
- Other Apple components that are not CoreGraphics in these three notes. Do not treat a Safari-only or Kernel-only advisory as coverage for 86950.
- Non-Apple platforms. This is an Apple CoreGraphics issue, not a cross-OS image library CVE.
One operator check
On iPhone or iPad: Settings → General → About and read the Software Version line. You want 26.7.1 (or newer) for this train.
On Mac, print the product version from Terminal:
sw_vers
# ProductVersion should be 15.8.1 (Sequoia) or 26.7.1 (Tahoe), or newer on that train
Anything below those fixed builds on a supported device is still open for this KEV row. MDM and inventory tools should flag Software Version / ProductVersion the same way.
How to fix
Install Apple's security updates published 2026-09-28:
- iPhone / iPad: Settings → General → Software Update → install iOS 26.7.1 or iPadOS 26.7.1.
- Mac on Sequoia: System Settings → General → Software Update → install macOS Sequoia 15.8.1.
- Mac on Tahoe: System Settings → General → Software Update → install macOS Tahoe 26.7.1.
Managed fleets: push the same builds through your MDM channel (ABM/ASM, Jamf, Intune, Kandji, or whatever you already use for Apple OS). After install, re-check Settings → General → About or sw_vers. Federal agencies under BOD 26-04 also owe forensic triage; KEV due date is 2026-10-02.
What this is not
This is not a wormable unauthenticated network RCE that sprays every Apple device on the internet with no user action. It needs processing of a maliciously crafted file, and Apple frames known exploitation as an extremely sophisticated attack against specific targeted individuals on older iOS. Still: CISA KEV today, Apple's own exploitation acknowledgment, and a three-day federal due date.
References
- Apple: About the security content of iOS 26.7.1 and iPadOS 26.7.1
- Apple: About the security content of macOS Tahoe 26.7.1
- Apple: About the security content of macOS Sequoia 15.8.1
- CISA Known Exploited Vulnerabilities catalog (CVE-2026-86950, dateAdded 2026-09-29, dueDate 2026-10-02, catalogVersion 2026.09.29, BOD 26-04)
- NVD CVE-2026-86950
- Full Disclosure Sep/89, Sep/90, Sep/91
Continue reading
All posts
BREAKING: Unauthenticated NetScaler RCE hits every appliance (CVE-2026-88771)
How to fix CVE-2026-88771: upgrade NetScaler ADC/Gateway to 14.1-73.37 or 13.1-64.23

WordPress page template include hits CISA KEV
How to fix CVE-2026-87902: upgrade WordPress to 7.1.2 (or your branch patch).

SharePoint code injection hits CISA KEV
How to fix CVE-2026-65660: upgrade SharePoint Server to the August 2026 fixed builds (SE 16.0.19725.20522 / 2019 16.0.10417.20198 / 2016 16.0.5565.1001)
