SECURITYHIGHCVE-2026-86950

CVE-2026-86950: Apple CoreGraphics Out-of-Bounds Write Enables Arbitrary Code Execution

An out-of-bounds write in Apple CoreGraphics lets a malicious file trigger code execution on iOS, iPadOS, and macOS; CVSS 8.8, patched September 28.

Dylan H.

Security Team

September 29, 2026
7 min read
CVE-2026-86950: Apple CoreGraphics Out-of-Bounds Write Enables Arbitrary Code Execution

Affected Products

  • iOS versions prior to 26.7.1 (iPhone 11 and later)
  • iPadOS versions prior to 26.7.1 (iPad Pro 12.9-inch 3rd gen and later, iPad Pro 11-inch 1st gen and later, iPad Air 3rd gen and later, iPad 8th gen and later, iPad mini 5th gen and later)
  • macOS Tahoe versions prior to 26.7.1
  • macOS Sequoia versions prior to 15.8.1

Overview

Apple has patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics — the low-level framework macOS, iOS, and iPadOS use for 2D vector graphics, image rendering, and text drawing. Processing a maliciously crafted file can corrupt memory in a way that leads to arbitrary code execution on the affected device.

The flaw was reported to Apple by Meta's product security team and was fixed on September 28, 2026 across iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Apple's advisory states it is aware of a report that the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals" running iOS versions earlier than iOS 27. Because active exploitation was confirmed prior to patch availability, CVE-2026-86950 has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, and this is the seventh Apple zero-day fixed in 2026.

This advisory focuses on the technical details of the vulnerability itself and the patch/mitigation guidance for administrators; a companion piece on the targeted-attack activity is covered separately.


Technical Details

FieldValue
CVE IDCVE-2026-86950
ComponentCoreGraphics
Vulnerability ClassOut-of-bounds write (memory corruption)
SeverityHigh (CVSS 8.8)
CVSS v3.1 VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ImpactArbitrary code execution
Exploitation StatusExploited in the wild prior to patch; listed in CISA KEV
Reported ByMeta Product Security
PatchedSeptember 28, 2026

How It Works

CoreGraphics (also known as Quartz 2D) is the rendering engine underneath nearly every graphics- and document-handling code path on Apple platforms, including image decoding, PDF rendering, and font/text layout. Apple's advisory describes the root cause simply: "An out-of-bounds write issue was addressed with improved bounds checking." In practice, this class of bug occurs when a parser inside CoreGraphics computes a buffer offset or allocation size from attacker-controlled data in the file (for example, a dimension, object count, or table length embedded in an image or document format) and then writes beyond the bounds of the allocated buffer using that value.

Because CoreGraphics sits underneath so many file-handling surfaces — image previews, PDF viewers, message attachments, and web content rendering — a single malformed file is enough to reach the vulnerable code path. The CVSS vector (AV:N, PR:N, UI:R) is consistent with a scenario where a victim only needs to view or open a delivered file (e.g., via a link preview, attachment, or embedded image) for the corrupted-memory write to occur; no authentication or elevated privileges are required on the attacker's side. Apple has not published the specific file format, parser, or code path involved, which is standard practice for actively exploited issues to slow attacker re-engineering of the bug.


Impact Assessment

Who Is At Risk

  • Any iPhone (11 and later) running iOS versions prior to 26.7.1
  • Any supported iPad model running iPadOS versions prior to 26.7.1 (iPad Pro 12.9-inch 3rd gen+, iPad Pro 11-inch 1st gen+, iPad Air 3rd gen+, iPad 8th gen+, iPad mini 5th gen+)
  • Mac systems running macOS Tahoe prior to 26.7.1 or macOS Sequoia prior to 15.8.1
  • Organizations with high-value or high-profile individuals (executives, journalists, activists, government personnel) whose devices are more likely to be selected for the kind of targeted, low-volume exploitation Apple describes
  • Fleets with delayed patch rollout (MDM-managed devices awaiting a deployment window, or personal devices that have deferred iOS/macOS updates)

Apple's newest platform generation — iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 — was not affected and shipped with no CVE-numbered fixes, indicating the underlying flaw was already absent or independently remediated in the CoreGraphics code path used by that release train.

Potential Attack Chains

  1. Delivery — An attacker delivers a maliciously crafted file to the target through a vector CoreGraphics will process automatically or with minimal interaction: a web page, an email or messaging attachment, or an embedded image/link preview.
  2. Memory Corruption — When the target's device (or an app that calls into CoreGraphics) renders or previews the file, the out-of-bounds write corrupts heap memory in a way the attacker has pre-arranged.
  3. Code Execution — The corrupted memory state is leveraged to redirect execution, typically as the entry point of a larger exploit chain (the CVSS C:H/I:H/A:H impact ratings indicate full compromise of confidentiality, integrity, and availability once triggered).
  4. Post-Exploitation — In the attacks Apple references as "extremely sophisticated," this type of primitive is usually chained with a sandbox escape and/or privilege escalation bug to achieve persistent access or data exfiltration — consistent with previous CoreGraphics/ImageIO-class zero-days used in targeted mobile spyware campaigns.

Mitigation

Immediate Actions

  • Update immediately to iOS 26.7.1 / iPadOS 26.7.1 (or iOS/iPadOS 27.0.1 if already on the new platform generation) on all supported iPhones and iPads
  • Update Macs to macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1, depending on the installed major version
  • Push the update fleet-wide via MDM rather than waiting on end-user self-service, given confirmed in-the-wild exploitation
  • Federal civilian agencies and KEV-bound organizations: treat this as a binding remediation item — CISA's KEV listing for actively exploited flaws typically carries a short remediation window (commonly 72 hours to a few weeks depending on the applicable directive)

Detection Opportunities

  • Review MDM/UEM inventory for devices still reporting iOS/iPadOS versions ≤ 26.7 or macOS Sequoia ≤ 15.8 / macOS Tahoe ≤ 26.7 after the patch window closes
  • Where available, review mobile threat defense (MTD) or endpoint telemetry for unexpected crashes in rendering/preview processes (Messages, Mail, Safari, Preview, QuickLook) around the time a suspicious file or link was received
  • High-risk individuals should consider Apple's Lockdown Mode, which restricts complex file/message parsing surfaces (including many attachment previews) and materially reduces exposure to this class of zero-click or one-click memory-corruption bug
  • Security teams supporting at-risk personnel can request Apple's threat notification history and correlate with device update timelines

Defence-in-Depth

  • Enable Lockdown Mode for executives, journalists, dissidents, or other individuals with an elevated targeting profile
  • Keep automatic updates enabled for iOS, iPadOS, and macOS so future CoreGraphics-class fixes land without manual intervention
  • Enforce a maximum patch-lag policy (e.g., "no device more than N days behind the latest security update") via MDM compliance rules, with conditional access tied to that policy
  • Treat image- and document-preview surfaces (Messages, Mail, Safari, Quick Look) as untrusted parsers, and where policy allows, disable automatic link/attachment previews for high-risk user groups

Background

CoreGraphics vulnerabilities are a recurring theme in Apple's zero-day disclosures because the framework is a mandatory dependency for nearly every visual rendering path on the platform — from the Photos app to Safari's image decoding to PDF previews in Mail and Messages. Bugs in this layer are attractive to sophisticated attackers precisely because they offer broad reach (almost any app that displays an image or document touches CoreGraphics) with a comparatively small, well-understood attack surface to fuzz and weaponize.

CVE-2026-86950 is Apple's seventh zero-day patched in 2026, continuing a pattern the company has faced for several consecutive years of memory-safety bugs in its graphics and media-parsing stack being caught in active, narrowly targeted exploitation before a fix ships. As in prior cases, Apple has not disclosed the delivery mechanism, the specific victims, or how the bug was discovered to have been exploited beyond crediting Meta's product security team with the report — consistent with the company's standard practice for actively exploited issues.


References