CVE-2026-86950

HIGH POC Pub 28/09 Upd 29/09

Overview

This vulnerability is an out-of-bounds write flaw caused by improper bounds checking during file processing in Apple iOS and iPadOS. The root cause lies in the failure to correctly validate input size or index values, leading to memory corruption. The affected components are the file parsing routines within the operating system's media or document handling subsystems.

Vulnerability Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Impact

An attacker can achieve arbitrary code execution by exploiting this vulnerability, enabling full control over the affected device. Exploitation requires the victim to open or process a malicious file, which may be delivered via email, messaging, or other file transfer methods. Successful exploitation can result in complete system compromise, data theft, or persistent unauthorized access, impacting targeted individuals or organizations with sensitive data.

Solution

Apple addressed this vulnerability by releasing security updates in iOS 26.7.1 and iPadOS 26.7.1, as well as macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1. Users and administrators should apply these updates promptly to mitigate the risk. Detailed patch instructions and advisory information are available at Apple's official support pages: https://support.apple.com/en-us/149226, https://support.apple.com/en-us/149228, and https://support.apple.com/en-us/149229.

EPSS vs KEV Prediction — Evolution (30 days)

Affected Products

No CPE information available.

Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

GitHub PoCs (1)

Repository Author Stars Forks Date Link
DeAurity/CVE-2026-86950-POC
Out-of-bounds Write (CWE-787)
DeAurity 0 0 2026-09-28 View
Exploited in Wild CONFIRMED
Ransomware NOT ASSOCIATED
Attacker Interest HIGH
Sightings Extensive activity

Threat Feed

5 events
2026-09-29
Threat Sensor Sighting — Extensive activity

Sighting activity recorded

2026-09-28
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-09-28
Detected as Exploited in the Wild

Active exploitation confirmed — vendor: Apple, product: ipados

2026-09-28
PoC Published (1 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

Detected as Exploited in the Wild (118 sightings)

Active exploitation confirmed with 118 sighting(s)

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Highlighted stages are those attackers typically reach when exploiting this CVE. Heuristic based on CWE families — refined by ML classifier when available.

Attack Vectors ML

Buffer Overflow
100% buffer_overflow
Remote Code Execution
53% rce

MITRE ATT&CK Techniques (0)

ATT&CK techniques pending

Techniques are derived from this CVE's kill chains once ML classification completes.

CAPEC Attack Patterns

No CAPEC pattern mapped to this CVE.

Red Team Playbook

AtomicRedTeam integration in progress

Executable commands will be auto-mapped to each ATT&CK technique of this CVE.

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (4)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-86950
support.apple.com
GitHub CVE
https://support.apple.com/en-us/149226
support.apple.com
GitHub CVE
https://support.apple.com/en-us/149228
support.apple.com
GitHub CVE
https://support.apple.com/en-us/149229