CVE-2026-86950
Overview
This vulnerability is an out-of-bounds write flaw caused by improper bounds checking during file processing in Apple iOS and iPadOS. The root cause lies in the failure to correctly validate input size or index values, leading to memory corruption. The affected components are the file parsing routines within the operating system's media or document handling subsystems.
Vulnerability Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Impact
An attacker can achieve arbitrary code execution by exploiting this vulnerability, enabling full control over the affected device. Exploitation requires the victim to open or process a malicious file, which may be delivered via email, messaging, or other file transfer methods. Successful exploitation can result in complete system compromise, data theft, or persistent unauthorized access, impacting targeted individuals or organizations with sensitive data.
Solution
Apple addressed this vulnerability by releasing security updates in iOS 26.7.1 and iPadOS 26.7.1, as well as macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1. Users and administrators should apply these updates promptly to mitigate the risk. Detailed patch instructions and advisory information are available at Apple's official support pages: https://support.apple.com/en-us/149226, https://support.apple.com/en-us/149228, and https://support.apple.com/en-us/149229.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
DeAurity/CVE-2026-86950-POC
Out-of-bounds Write (CWE-787)
|
DeAurity | 0 | 0 | 2026-09-28 | View |
Threat Feed
5 eventsSighting activity recorded
Sighting activity recorded
Active exploitation confirmed — vendor: Apple, product: ipados
Proof-of-concept code is publicly available for this vulnerability
Active exploitation confirmed with 118 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.
Attack Vectors ML
MITRE ATT&CK Techniques (0)
Techniques are derived from this CVE's kill chains once ML classification completes.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
Executable commands will be auto-mapped to each ATT&CK technique of this CVE.
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-86950 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/149226 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/149228 |
| support.apple.com |
GitHub CVE
|
https://support.apple.com/en-us/149229 |