Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4668 articles · 224795 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-86950KEVEXPLOITEDPATCHED
apple · ios and ipados

CVE-2026-86950: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 2

Description

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Affected Products

VendorProductVersions
appleios and ipados0, 0, 0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
appleioscert_advisory90%
applemacoscert_advisory90%
appleipadoscert_advisory90%

References

  • https://support.apple.com/en-us/149226
  • https://support.apple.com/en-us/149228
  • https://support.apple.com/en-us/149229

Related News (10 articles)

Tier B
CCCS Canada12h ago
Apple security advisory (AV26-971)
→ No new info (linked only)
Tier B
BSI Advisories15h ago
[NEU] [hoch] Apple iOS, iPadOS, macOS Tahoe und Sequoia: Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier D
Help Net Security15h ago
Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)
→ No new info (linked only)
Tier D
SecurityWeek19h ago
Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’ 
→ No new info (linked only)
Tier E
Full Disclosure19h ago
APPLE-SA-09-28-2026-3 macOS Sequoia 15.8.1
→ No new info (linked only)
Tier E
Full Disclosure19h ago
APPLE-SA-09-28-2026-2 macOS Tahoe 26.7.1
→ No new info (linked only)
Tier E
Full Disclosure19h ago
APPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1
→ No new info (linked only)
Tier B
CERT-FR1d ago
Vulnérabilité dans les produits Apple (29 septembre 2026)
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-86950 | Apple iOS/iPadOS/macOS prior 26.7.1/15.8.1 out-of-bounds write
→ No new info (linked only)
Tier D
The Hacker News1d ago
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
26.7.115.8.1
PublishedSep 28, 2026
Trending Score140🔥
Source articles10
Independent8
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-65400EXPKEV
CVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS
Trending: 60
MEDIUMCVE-2026-84635
CVE-2026-84635: A logic issue was addressed with improved state management. This issue is fixed in Safari 27, iOS 27 and iPadOS 27, macO
Trending: 42
MEDIUMCVE-2026-64778
CVE-2026-64778: The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS
Trending: 42
MEDIUMCVE-2026-64753
CVE-2026-64753: A permissions issue was addressed by removing the vulnerable code. This issue is fixed in Safari 27, iOS 27 and iPadOS 2
Trending: 42
MEDIUMCVE-2026-64715
CVE-2026-64715: A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10
Trending: 42

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Sep 28, 2026
Added to CISA KEV
Sep 28, 2026
Discovered by ZDM
Sep 28, 2026
Actively Exploited
Sep 29, 2026
Patch Available
Sep 29, 2026