U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini
September 30, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog.

This week, Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability CVE-2026-86950 in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when the system processes a specially crafted file.

The vulnerability affects iOS 26.7 and earlier versions before iOS 27, as well as iPadOS 26.7 and earlier and supported versions of macOS Tahoe and macOS Sequoia. Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the issue.

“Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” reads Apple’s advisory. “Description: “An out-of-bounds write issue was addressed with improved bounds checking.”

Apple says it knows of a report that the flaw may have been exploited in an “extremely sophisticated attack against specific targeted individuals” running versions of iOS before iOS 27.

Apple hasn’t disclosed who was targeted, how many people were affected, whether the attacks succeeded, or when exploitation started. It also hasn’t explained how attackers delivered the malicious files. That leaves an important part of the attack chain unknown.

CoreGraphics handles graphics and rendering functions across Apple’s operating systems, including processing content such as images and PDFs. Attackers can trigger the flaw by tricking the victim into opening a malicious file sent through a web page, an email attachment, or a messaging application, However, Apple hasn’t confirmed any of these delivery methods for CVE-2026-86950.

That distinction matters. A crafted file doesn’t need to look like an obvious executable for a vulnerability in a system component that processes content to become useful to an attacker. The security boundary can be crossed while the operating system is simply doing what it’s designed to do: interpreting a file.

Meta Product Security discovered and reported the vulnerability to Apple. The involvement of Meta is particularly interesting because the company has previously identified attacks involving Apple vulnerabilities and targeted users of its messaging platforms.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the flaw by October 2nd, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.