Apple patched CoreGraphics for a targeted iOS report. iOS 27 is not the fleet.
CVE-2026-86950 is an out-of-bounds write Meta found. Apple says a sophisticated attack on iOS before 27. CISA has not put it on KEV.
Bottom line up front
CONFIRMED Apple published CVE-2026-86950 on 28 September 2026. It is an out-of-bounds write in CoreGraphics. The vendor impact line is: processing a maliciously crafted file may lead to arbitrary code execution. The reporter is Meta Product Security. The fix is improved bounds checking.
The exploitation claim is Apple’s, and it is narrower than the headlines.
Apple: it is “aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” That is CONFIRMED as Apple’s wording. It is not a named actor, not a victim count, not a file type, not a delivery path, and not a statement that Macs were hit.
Do not collapse four facts.
- This is not yesterday’s NetScaler. [CVE-2026-88771 / 88772](/posts/2026-09-28-citrix-netscaler-cve-2026-88771-88772-kev/) remain on KEV, due 30 September, default-config unauthenticated command execution on the perimeter. Today’s story is a client-side Apple bug with a targeted report. The NetScaler clock does not pause.
- iOS 27 is out of this CVE. Apple’s security-releases table for iOS 27.0.1 and macOS Golden Gate 27.0.1 (also 28 September) lists no published CVE entries. The lagging estate is iOS/iPadOS 26, macOS Sequoia 15, and macOS Tahoe 26.
- CISA has not elevated it. Live KEV catalog this morning is still
2026.09.27, count 1728, newest rows the two NetScaler CVEs. CVE-2026-86950 is not in the catalog. CISA-ADP’s SSVC enrichment on the CVE record, updated 29 September 03:55 UTC, still scores exploitation none, automatable no, technical impact total. Apple’s “may have been exploited” and CISA’s “none” can both be true at once: a targeted report is not a KEV row. - User interaction is in the only published CVSS. Apple did not score it. CISA-ADP’s secondary metric is CVSS 3.1 8.8
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. That is not an unauthenticated network worm. It is a file that has to be processed. Whether iMessage, Mail, Safari, or WhatsApp preview counts as “processing” for this bug is UNKNOWN — Apple did not say.
This is not a re-run of [Jade Sleet on an IT-services MacBook](/posts/2026-09-21-jade-sleet-it-services-flatroof-roofdeck/). That was a macOS implant with a delivery path SentinelOne could not prove on that host. This is a vendor zero-day in a graphics parser, with a targeted-iOS report and a same-day patch for the trains that still need it.
| Fact | Record |
|---|---|
| CVE | CVE-2026-86950 |
| Component | Apple CoreGraphics |
| CWE | CWE-787 (CISA-ADP secondary; Apple CNA did not publish a CWE) |
| Score | Apple: none. CISA-ADP: CVSS 3.1 8.8, UI:R |
| Fixed | iOS/iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1 |
| Not in the published fix list | iOS/iPadOS 27, macOS Golden Gate 27, watchOS / tvOS / visionOS 27.0.1, macOS Sonoma 14, iOS 18 |
| Exploitation | REPORTED by Apple (“may have been exploited… specific targeted individuals… iOS before iOS 27”). CISA KEV: not listed. CISA-ADP SSVC: exploitation none |
| Named actor | UNKNOWN |
| Delivery / file type | UNKNOWN |
| Ransomware use | UNKNOWN (no KEV row) |
| OT / process impact | None claimed |
What happened
Monday 28 September, Apple shipped a cluster of point releases. Four of them carry this CVE:
- iOS 26.7.1 and iPadOS 26.7.1 — iPhone 11 and later; iPad Pro 12.9-inch 3rd generation and later; iPad Pro 11-inch 1st generation and later; iPad Air 3rd generation and later; iPad 8th generation and later; iPad mini 5th generation and later
- macOS Tahoe 26.7.1
- macOS Sequoia 15.8.1
The three advisories use the same paragraph. Impact: processing a maliciously crafted file may lead to arbitrary code execution, plus the iOS-before-27 targeting sentence. Description: an out-of-bounds write, addressed with improved bounds checking. Credit: Meta Product Security.
CVE.org: reserved 8 September 2026, published 28 September 19:13 UTC. NVD: published 28 September 20:17 UTC, last modified 29 September 08:17 UTC, status Awaiting Analysis. The CNA product list is iOS/iPadOS affected below 26.7.1, and macOS affected below 15.8.1 and below 26.7.1.
The same day’s iOS 27.0.1, iPadOS 27.0.1, macOS Golden Gate 27.0.1, watchOS 27.0.1, and visionOS 27.0.1 are listed on Apple’s security-releases page with no published CVE entries. Apple’s exploitation sentence is limited to iOS before 27. That is the vendor’s own blast-radius statement. It does not prove Macs were attacked. It also does not prove Macs are safe if they are still on Sequoia or Tahoe — the same CoreGraphics bug is patched there.
There was no iOS 18.x and no macOS Sonoma 14.x security content for this CVE on 28 September. Devices that cannot take iOS 26 or Sequoia/Tahoe are not covered by the published fixes. Whether they are vulnerable is UNKNOWN in the CNA record; do not assume they are out of scope just because Apple did not ship them a build.
KEV catalog 2026.09.27 (released 27 September 21:30 UTC, count 1728) did not move overnight. CISA’s public alerts page still tops out at the 27 September NetScaler pair. This CVE is not there.
Why it matters
CoreGraphics is not an app. It is the 2-D graphics, image, and document-rendering stack the OS uses when something draws a PDF, a picture, or a page. A bug there is a parser bug. Parser bugs are how mercenary spyware has repeatedly landed on iPhone without a useful “don’t open attachments” speech.
That pattern-match is ASSESSED, not CONFIRMED. Apple did not name a spyware vendor, a messaging app, or a zero-click preview. Meta as the finder is consistent with WhatsApp-adjacent reporting in prior years. SecurityWeek asked Meta whether this one went through WhatsApp and, as of their 29 September piece, had no answer. Treat “WhatsApp zero-click” as UNKNOWN. Treat “targeted iOS, sophisticated, Meta-reported CoreGraphics” as the actual record.
For a CISO the operational fact is simpler than the spyware lore: a large share of managed iPhones and Macs will still be on iOS 26 and macOS 15/26 two weeks after iOS 27 / Golden Gate shipped (14 September). Those trains just received a same-day security point release. MDM rings that are waiting for “the iOS 27 project” are holding the vulnerable parser.
It is also a sequencing problem. Yesterday’s Daily Top is still the interrupt for internet-facing ADC/Gateway. Today’s Apple row is the interrupt for the endpoint and mobile queue. They are not substitutes.
Who / what is affected
In for the published CVE, until the listed build:
- iPhone / iPad still on iOS/iPadOS 26.7 or earlier 26.x (and, per the CNA “below 26.7.1” encoding, any earlier iOS/iPadOS train Apple considers in-scope for that product name)
- Macs on macOS Sequoia below 15.8.1
- Macs on macOS Tahoe below 26.7.1
Out of this CVE, per Apple’s own tables and wording:
- Devices already on iOS 27 / iPadOS 27 (27.0.1 has no CVE for this)
- Macs already on macOS Golden Gate 27
- The targeted-exploitation sentence is iOS-only in Apple’s text
Not in the 28 September fix list — status UNKNOWN, do not invent a patch:
- macOS Sonoma 14
- iOS 18 and older iPhones/iPads that cannot install iOS 26 (Apple’s last iOS 18.7.10 security content in this table was 17 August)
- watchOS, tvOS, visionOS — 27.0.1 has no published CVE; Apple did not list a 26.x CoreGraphics fix for them either
Enterprise blast radius is the MDM lagging ring, executive and journalist devices that defer major upgrades, and any air-gapped or kiosk iPad still pinned on 26.x. This is not a mass-scan-and-shell story. It is a high-value-target story with a parser that also exists on the corporate Mac.
Technical context
Class: CWE-787 out-of-bounds write. Trigger: a maliciously crafted file processed by CoreGraphics. Result, per Apple: arbitrary code execution. Fix: bounds checking.
Attack prerequisites that are in the public record:
- The file has to be processed. CISA-ADP encoded that as UI:R.
- No privileges required, network vector, low complexity — that is the CVSS, not a statement that the file arrives unattended.
- No published workaround. The control is the OS build.
Attack prerequisites that are not in the public record:
- File format (PDF, image, font, CGPath — UNKNOWN)
- Whether Lockdown Mode would have blocked the reported attack (UNKNOWN)
- Whether preview-without-tap is enough (UNKNOWN)
- Sandbox escape, kernel follow-on, or persistence after the CoreGraphics process is owned (UNKNOWN)
ATT&CK, mapped only as far as the vendor text supports:
| Tactic | ID | Notes |
|---|---|---|
| Exploitation for Client Execution | T1203 | CONFIRMED as the class Apple describes |
| User Execution: Malicious File | T1204.002 | Matches UI:R and “crafted file”; delivery app UNKNOWN |
| Phishing: Spearphishing Attachment | T1566.001 | ASSESSED possible; not stated |
| Drive-by Compromise | T1189 | ASSESSED possible if a previewer invokes CoreGraphics; not stated |
RWP is not publishing a crash PoC, a file structure, or a debugger recipe. Defenders do not need one to push 26.7.1.
Threat / exploitation status
| Claim | Status | Source |
|---|---|---|
| CVE-2026-86950 exists; CoreGraphics OOB write; arbitrary code execution via crafted file | CONFIRMED | Apple HT 149226 / 149228 / 149229; CVE.org; NVD |
| Patched in iOS/iPadOS 26.7.1, macOS 15.8.1, macOS 26.7.1 | CONFIRMED | Same |
| Apple is aware of a report of exploitation in an extremely sophisticated attack on specific targeted individuals, iOS before 27 | CONFIRMED as Apple statement | Apple impact line, all three advisories |
| In-the-wild mass exploitation / wormable | NOT supported | UI:R; “specific targeted individuals” |
| Named actor, victim sector, file type, messaging app | UNKNOWN | None in Apple, NVD, CISA |
| WhatsApp as the vector because Meta reported it | UNKNOWN | SecurityWeek: no Meta confirmation as of 29 Sep |
| On CISA KEV | CONFIRMED absent | Catalog 2026.09.27, count 1728; no 86950 row |
| CISA-ADP SSVC exploitation | CONFIRMED “none” as of 29 Sep 03:55 UTC | CVE ADP container |
| iOS 27 / macOS 27 affected | NOT supported by Apple’s CVE tables | 27.0.1 “no published CVE entries” |
| Macs exploited in the reported attack | UNKNOWN | Apple limited the sentence to iOS |
| Public exploit / PoC | UNKNOWN in the primary record | RWP is not hunting one |
| OT / process impact | None claimed | — |
Confidence on the patch, the CVE, and Apple’s wording: high. Confidence that this is mercenary spyware rather than a one-off targeted implant: moderate — the language and the finder match that cluster; the public record does not name it. Confidence on campaign size and delivery: low.
What defenders should do
- Split the Apple fleet by train, not by “we’re on iOS 27 eventually.” Count devices on iOS 26, iOS 18, Sequoia 15, Tahoe 26, Golden Gate 27. The ticket for 86950 is 26.7.1 / 15.8.1 / 26.7.1, not the 27 upgrade project. Devices already on 27 do not take this CVE; they still need whatever 27.0.1 actually fixes (Apple published no CVE for it).
- Push the point release through MDM now. Supervised iPhone/iPad: enforce 26.7.1 as a minimum on the 26 train. Mac: 15.8.1 or 26.7.1. Do not wait for a KEV row. CISA’s SSVC “none” is not a reason to sit on a vendor-reported targeted parser bug.
- Treat high-risk users as a separate queue. Executives, journalists, diplomats, and anyone already on a heightened-risk profile should get the build first, and Lockdown Mode should be a conversation — as a general mercenary-spyware control, not because Apple said Lockdown Mode stops this bug (it did not).
- Do not hunt IOCs Apple did not publish. There are no hashes, no domains, no process names in the advisory. A CoreGraphics crash after a weird attachment is interesting; it is not a detection signature. If you have an EDR story for iOS, it is MDM compliance and unexpected configuration profiles, not a YARA rule for this CVE.
- Do not skip Sonoma / iOS 18 and call them done. They are not in the fix list. Inventory them. If Apple later ships 14.x / 18.x content, that is a material development. Until then, compensating controls are the only honest answer: reduce who can send those devices files, and accelerate hardware that can take a patched train.
- Keep yesterday’s perimeter clock. NetScaler CVE-2026-88771 / 88772 are due 30 September, forensic triage Yes, no workaround. SharePoint CVE-2026-65660, WordPress CVE-2026-87902, and MikroTik CVE-2026-67279 were due 28 September. An iPhone parser does not close an ADC.
RWP assessment
Score 8.4.
Highest-leverage development since yesterday’s NetScaler KEV pair is a same-day Apple security point release for a CoreGraphics out-of-bounds write that Apple itself ties to a targeted, sophisticated iOS report, with Meta as the finder, and with the vulnerable estate defined as everything still on iOS 26 / Sequoia / Tahoe. Evidence quality is high for the vulnerability and the patch (Apple CNA + three HT pages + NVD). Evidence quality is only moderate for exploitation: Apple’s “may have been exploited” is real, CISA has not listed KEV, and CISA-ADP SSVC still says none.
It outranks a second day on NetScaler because yesterday already shipped CTX697096, the two KEV rows, and the Wednesday due date; the clock is not a new finding. It outranks Microsoft’s Storm-3168 / JadePuffer Azure write-up because that primary is 25 September — before yesterday’s Daily Top — and Monday’s amplification is secondary coverage, not a new technical record. It outranks the official MCP Python SDK OAuth credential-theft advisory (GHSA-qx49-fqc8-xw99, 28 September, no CVE as of this morning, no in-the-wild claim). It outranks Keio’s ransomware notice: the operator said trains are running; an IT compromise at a railway group is not confirmed OT impact.
What we are not saying: that this is a mass iPhone worm; that WhatsApp delivered it; that iOS 27 needs this CVE’s patch; that Macs were in the reported attack; that CISA has ordered a three-day clock; that a NetScaler in an industrial DMZ, or a railway booking system, is this story.
What we are watching
- Whether CISA adds CVE-2026-86950 to KEV, and whether the SSVC exploitation field flips from none.
- Whether Apple or Meta names a delivery app, a file format, or a follow-on implant.
- Whether Sonoma 14 or iOS 18 receives a late build.
- Whether independent researchers publish a crash signature Apple will stand behind — still not a reason to delay 26.7.1.
- NetScaler 88771/88772 due 30 September.
- Storm-3168 / JadePuffer Azure service-principal destruction (Microsoft 25 September) if CISA, MSRC, or Microsoft names a new tenant, a new initial-access CVE, or ransomware use. The 25 September blog is not today’s lead.
Sources
- Apple — iOS 26.7.1 and iPadOS 26.7.1 security content
- Apple — macOS Tahoe 26.7.1 security content
- Apple — macOS Sequoia 15.8.1 security content
- Apple — security releases
- CVE-2026-86950 · NVD
- CISA — KEV JSON catalog
2026.09.27 - CISA — Known Exploited Vulnerabilities Catalog
- The Hacker News — Apple patches CoreGraphics flaw possibly exploited in targeted attacks
- SecurityWeek — Apple patches Meta-reported zero-day
- BleepingComputer — Apple patches CoreGraphics zero-day
Sources
- Apple — Security content of iOS 26.7.1 and iPadOS 26.7.1
- Apple — Security content of macOS Tahoe 26.7.1
- Apple — Security content of macOS Sequoia 15.8.1
- Apple — Security releases
- NVD — CVE-2026-86950
- CVE — CVE-2026-86950
- CISA — KEV JSON feed catalog 2026.09.27
- CISA — Known Exploited Vulnerabilities Catalog
- The Hacker News — Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
- SecurityWeek — Apple Patches Meta-Reported Zero-Day
- BleepingComputer — Apple patches CoreGraphics zero-day flaw exploited in attacks