AppleCVE-2026-86950
Apple iOS and iPadOS: out-of-bounds write
High8.8CVE-2026-86950 · Published Sep 28, 2026 · updated Oct 1, 2026
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| iOS and iPadOS Product | < 26.7.1 | 26.7.1 |
| macOS Product | < 15.8.1 | 15.8.1 |
| < 26.7.1 | 26.7.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-787
- www.cve.org/CVERecord?id=CVE-2026-86950
- nvd.nist.gov/vuln/detail/CVE-2026-86950
- support.apple.com/en-us/149226
- support.apple.com/en-us/149228
- support.apple.com/en-us/149229
- seclists.org/fulldisclosure/2026/Sep/89
- seclists.org/fulldisclosure/2026/Sep/90
- seclists.org/fulldisclosure/2026/Sep/91
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86950
More Apple advisories
All Apple| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 23 | Apple FileMaker Server: buffer overflow | High7.8 | 26.0.3 |
| Sep 23 | Apple FileMaker Server: out-of-bounds read | Critical9.1 | 26.0.3 |
| Sep 23 | Apple FileMaker Server: insecure direct object reference | Critical9.1 | 26.0.3 |
| Sep 23 | Apple FileMaker Pro: untrusted search path | High7.3 | 26.0.3 |
| Sep 14 | Apple macOS: path traversal | Medium5.5 | 14.8.8+1 more |
| Sep 14 | Apple iOS and iPadOS: out-of-bounds read | Medium5.5 | 27+2 more |