Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Out‑of‑Bounds Write in Apple CoreGraphics (CVE‑2026‑86950) Enables Arbitrary Code Execution

Apple’s CoreGraphics component contains an out‑of‑bounds write (CVE‑2026‑86950) that allows arbitrary code execution and is listed in CISA’s KEV catalog. The flaw affects iOS, iPadOS, and macOS versions prior to the latest patches, highlighting the need for rigorous vulnerability‑management and audit‑ready remediation.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 securityaffairs.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
securityaffairs.com

Critical Out‑of‑Bounds Write in Apple CoreGraphics (CVE‑2026‑86950) Enables Arbitrary Code Execution

What It Is – Apple disclosed a zero‑day out‑of‑bounds write in the CoreGraphics component that can lead to arbitrary code execution when a specially crafted file is processed. The flaw is tracked as CVE‑2026‑86950 and carries a CVSS 8.8 score.

Exploitability – The vulnerability is listed in the U.S. CISA Known Exploited Vulnerabilities (KEV) catalog, indicating that active exploitation against targeted individuals has been observed. No public proof‑of‑concept is required; exploitation occurs via malicious files.

Affected Products – iOS 26.7 and earlier (pre‑iOS 27), iPadOS 26.7 and earlier, macOS Tahoe, and macOS Sequoia (all prior to the released patches). Apple issued updates: iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a robust vulnerability‑management control that ensures timely detection, risk assessment, and patch deployment across all endpoints.
  • Provides auditors with concrete evidence that an organization can track remediation actions and maintain a defensible audit trail for patch‑level compliance.
  • Highlights that a single unpatched component can break the security boundary, underscoring the importance of continuous monitoring of software inventory and version compliance.

Recommended Actions

  • Deploy Apple’s security updates immediately on all affected iOS, iPadOS, and macOS devices.
  • Verify patch status through automated asset‑inventory tools and record remediation dates for audit evidence.
  • Enable logging of CoreGraphics‑related crashes or anomalous file processing to detect potential exploitation attempts.
  • Update your vulnerability‑management policy to include rapid response timelines for KEV‑listed flaws.

Source: Security Affairs – CISA adds Apple Multiple Products flaw to KEV catalog

📰 Original Source
https://securityaffairs.com/200069/security/u-s-cisa-adds-apple-multiple-products-flaw-to-its-known-exploited-vulnerabilities-catalog.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →