Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical CoreGraphics Out‑of‑Bounds Write (CVE‑2026‑86950) Lets Attackers Execute Code on iOS and macOS Devices

Apple released patches for CVE‑2026‑86950, a CoreGraphics out‑of‑bounds write that can enable arbitrary code execution on iPhone, iPad, and Mac. The vulnerability underscores the need for continuous patch‑management evidence to satisfy audit requirements across frameworks.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 malwarebytes.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
malwarebytes.com

Apple CoreGraphics Out‑of‑Bounds Write (CVE‑2026‑86950) Enables Code Execution on iPhone, iPad, and Mac

What Happened — Apple disclosed CVE‑2026‑86950, an out‑of‑bounds write in the CoreGraphics framework that can be triggered by a maliciously crafted image or PDF. Successful exploitation allows an attacker to execute arbitrary code on iOS, iPadOS, and macOS devices. Apple has released patches in iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a continuous patch‑management control that records timely updates as evidence of due diligence.
  • Highlights the importance of defensible audit trails showing that known critical vulnerabilities are remediated across all endpoints.
  • Aligns with the Control Mapping capability, which lets organizations map patch‑remediation to a single control objective that satisfies multiple frameworks (e.g., NIST CSF 2.0, ISO 27001).

Who Is Affected — Consumers, enterprises, and service providers that rely on Apple iPhones, iPads, or Macs for everyday operations.

Recommended Actions

  • Verify that all Apple devices are running the latest versions (iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1).
  • Integrate automated patch‑status checks into your continuous monitoring platform.
  • Document remediation evidence against the “maintain up‑to‑date software” control objective for audit readiness.

Source: Malwarebytes Labs

Technical Notes — The flaw resides in CoreGraphics, an Apple graphics‑processing library. It is an out‑of‑bounds write (memory corruption) that can be triggered by a crafted file, leading to remote code execution. Apple reports at least one highly targeted exploitation attempt against pre‑iOS 27 devices. Source: Apple Security Update

📰 Original Source
https://www.malwarebytes.com/blog/bugs/2026/09/update-your-iphone-ipad-or-mac-flaw-could-run-attackers-code ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →