← Back to CVE List
Vulnerability Intelligence Report
Apple Multiple Products Out-of-Bounds Write Vulnerability

CVE-2026-86950

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:0.81%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-787 ↗CWE-787 Out-of-bounds Write

Affected Products & Versions

Vendor Product Affected Versions
Apple iOS and iPadOS 0 < 26.7.1 (affected)
Apple macOS 0 < 15.8.1 (affected), 0 < 26.7.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
0.812%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityApple Inc. · Vendor · USA
Reserved2026-09-08T16:43:41
Published2026-09-28T19:13:52
Last Updated2026-09-29T14:58:23

LINK COPIED TO CLIPBOARD