Daily Top · Vulnerabilities / Endpoint

Apple patched CoreGraphics for a targeted iOS report. iOS 27 is not the fleet.

CVE-2026-86950 is an out-of-bounds write Meta found. Apple says a sophisticated attack on iOS before 27. CISA has not put it on KEV.

RWP Ventures · 2026-09-29 · event 2026-09-28 · 13 min read · priority 8.4

Bottom line up front

CONFIRMED Apple published CVE-2026-86950 on 28 September 2026. It is an out-of-bounds write in CoreGraphics. The vendor impact line is: processing a maliciously crafted file may lead to arbitrary code execution. The reporter is Meta Product Security. The fix is improved bounds checking.

The exploitation claim is Apple’s, and it is narrower than the headlines.

Apple: it is “aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” That is CONFIRMED as Apple’s wording. It is not a named actor, not a victim count, not a file type, not a delivery path, and not a statement that Macs were hit.

Do not collapse four facts.

  1. This is not yesterday’s NetScaler. [CVE-2026-88771 / 88772](/posts/2026-09-28-citrix-netscaler-cve-2026-88771-88772-kev/) remain on KEV, due 30 September, default-config unauthenticated command execution on the perimeter. Today’s story is a client-side Apple bug with a targeted report. The NetScaler clock does not pause.
  2. iOS 27 is out of this CVE. Apple’s security-releases table for iOS 27.0.1 and macOS Golden Gate 27.0.1 (also 28 September) lists no published CVE entries. The lagging estate is iOS/iPadOS 26, macOS Sequoia 15, and macOS Tahoe 26.
  3. CISA has not elevated it. Live KEV catalog this morning is still 2026.09.27, count 1728, newest rows the two NetScaler CVEs. CVE-2026-86950 is not in the catalog. CISA-ADP’s SSVC enrichment on the CVE record, updated 29 September 03:55 UTC, still scores exploitation none, automatable no, technical impact total. Apple’s “may have been exploited” and CISA’s “none” can both be true at once: a targeted report is not a KEV row.
  4. User interaction is in the only published CVSS. Apple did not score it. CISA-ADP’s secondary metric is CVSS 3.1 8.8 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. That is not an unauthenticated network worm. It is a file that has to be processed. Whether iMessage, Mail, Safari, or WhatsApp preview counts as “processing” for this bug is UNKNOWN — Apple did not say.

This is not a re-run of [Jade Sleet on an IT-services MacBook](/posts/2026-09-21-jade-sleet-it-services-flatroof-roofdeck/). That was a macOS implant with a delivery path SentinelOne could not prove on that host. This is a vendor zero-day in a graphics parser, with a targeted-iOS report and a same-day patch for the trains that still need it.

FactRecord
CVECVE-2026-86950
ComponentApple CoreGraphics
CWECWE-787 (CISA-ADP secondary; Apple CNA did not publish a CWE)
ScoreApple: none. CISA-ADP: CVSS 3.1 8.8, UI:R
FixediOS/iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1
Not in the published fix listiOS/iPadOS 27, macOS Golden Gate 27, watchOS / tvOS / visionOS 27.0.1, macOS Sonoma 14, iOS 18
ExploitationREPORTED by Apple (“may have been exploited… specific targeted individuals… iOS before iOS 27”). CISA KEV: not listed. CISA-ADP SSVC: exploitation none
Named actorUNKNOWN
Delivery / file typeUNKNOWN
Ransomware useUNKNOWN (no KEV row)
OT / process impactNone claimed

What happened

Monday 28 September, Apple shipped a cluster of point releases. Four of them carry this CVE:

The three advisories use the same paragraph. Impact: processing a maliciously crafted file may lead to arbitrary code execution, plus the iOS-before-27 targeting sentence. Description: an out-of-bounds write, addressed with improved bounds checking. Credit: Meta Product Security.

CVE.org: reserved 8 September 2026, published 28 September 19:13 UTC. NVD: published 28 September 20:17 UTC, last modified 29 September 08:17 UTC, status Awaiting Analysis. The CNA product list is iOS/iPadOS affected below 26.7.1, and macOS affected below 15.8.1 and below 26.7.1.

The same day’s iOS 27.0.1, iPadOS 27.0.1, macOS Golden Gate 27.0.1, watchOS 27.0.1, and visionOS 27.0.1 are listed on Apple’s security-releases page with no published CVE entries. Apple’s exploitation sentence is limited to iOS before 27. That is the vendor’s own blast-radius statement. It does not prove Macs were attacked. It also does not prove Macs are safe if they are still on Sequoia or Tahoe — the same CoreGraphics bug is patched there.

There was no iOS 18.x and no macOS Sonoma 14.x security content for this CVE on 28 September. Devices that cannot take iOS 26 or Sequoia/Tahoe are not covered by the published fixes. Whether they are vulnerable is UNKNOWN in the CNA record; do not assume they are out of scope just because Apple did not ship them a build.

KEV catalog 2026.09.27 (released 27 September 21:30 UTC, count 1728) did not move overnight. CISA’s public alerts page still tops out at the 27 September NetScaler pair. This CVE is not there.

Why it matters

CoreGraphics is not an app. It is the 2-D graphics, image, and document-rendering stack the OS uses when something draws a PDF, a picture, or a page. A bug there is a parser bug. Parser bugs are how mercenary spyware has repeatedly landed on iPhone without a useful “don’t open attachments” speech.

That pattern-match is ASSESSED, not CONFIRMED. Apple did not name a spyware vendor, a messaging app, or a zero-click preview. Meta as the finder is consistent with WhatsApp-adjacent reporting in prior years. SecurityWeek asked Meta whether this one went through WhatsApp and, as of their 29 September piece, had no answer. Treat “WhatsApp zero-click” as UNKNOWN. Treat “targeted iOS, sophisticated, Meta-reported CoreGraphics” as the actual record.

For a CISO the operational fact is simpler than the spyware lore: a large share of managed iPhones and Macs will still be on iOS 26 and macOS 15/26 two weeks after iOS 27 / Golden Gate shipped (14 September). Those trains just received a same-day security point release. MDM rings that are waiting for “the iOS 27 project” are holding the vulnerable parser.

It is also a sequencing problem. Yesterday’s Daily Top is still the interrupt for internet-facing ADC/Gateway. Today’s Apple row is the interrupt for the endpoint and mobile queue. They are not substitutes.

Who / what is affected

In for the published CVE, until the listed build:

Out of this CVE, per Apple’s own tables and wording:

Not in the 28 September fix list — status UNKNOWN, do not invent a patch:

Enterprise blast radius is the MDM lagging ring, executive and journalist devices that defer major upgrades, and any air-gapped or kiosk iPad still pinned on 26.x. This is not a mass-scan-and-shell story. It is a high-value-target story with a parser that also exists on the corporate Mac.

Technical context

Class: CWE-787 out-of-bounds write. Trigger: a maliciously crafted file processed by CoreGraphics. Result, per Apple: arbitrary code execution. Fix: bounds checking.

Attack prerequisites that are in the public record:

Attack prerequisites that are not in the public record:

ATT&CK, mapped only as far as the vendor text supports:

TacticIDNotes
Exploitation for Client ExecutionT1203CONFIRMED as the class Apple describes
User Execution: Malicious FileT1204.002Matches UI:R and “crafted file”; delivery app UNKNOWN
Phishing: Spearphishing AttachmentT1566.001ASSESSED possible; not stated
Drive-by CompromiseT1189ASSESSED possible if a previewer invokes CoreGraphics; not stated

RWP is not publishing a crash PoC, a file structure, or a debugger recipe. Defenders do not need one to push 26.7.1.

Threat / exploitation status

ClaimStatusSource
CVE-2026-86950 exists; CoreGraphics OOB write; arbitrary code execution via crafted fileCONFIRMEDApple HT 149226 / 149228 / 149229; CVE.org; NVD
Patched in iOS/iPadOS 26.7.1, macOS 15.8.1, macOS 26.7.1CONFIRMEDSame
Apple is aware of a report of exploitation in an extremely sophisticated attack on specific targeted individuals, iOS before 27CONFIRMED as Apple statementApple impact line, all three advisories
In-the-wild mass exploitation / wormableNOT supportedUI:R; “specific targeted individuals”
Named actor, victim sector, file type, messaging appUNKNOWNNone in Apple, NVD, CISA
WhatsApp as the vector because Meta reported itUNKNOWNSecurityWeek: no Meta confirmation as of 29 Sep
On CISA KEVCONFIRMED absentCatalog 2026.09.27, count 1728; no 86950 row
CISA-ADP SSVC exploitationCONFIRMED “none” as of 29 Sep 03:55 UTCCVE ADP container
iOS 27 / macOS 27 affectedNOT supported by Apple’s CVE tables27.0.1 “no published CVE entries”
Macs exploited in the reported attackUNKNOWNApple limited the sentence to iOS
Public exploit / PoCUNKNOWN in the primary recordRWP is not hunting one
OT / process impactNone claimed—

Confidence on the patch, the CVE, and Apple’s wording: high. Confidence that this is mercenary spyware rather than a one-off targeted implant: moderate — the language and the finder match that cluster; the public record does not name it. Confidence on campaign size and delivery: low.

What defenders should do

  1. Split the Apple fleet by train, not by “we’re on iOS 27 eventually.” Count devices on iOS 26, iOS 18, Sequoia 15, Tahoe 26, Golden Gate 27. The ticket for 86950 is 26.7.1 / 15.8.1 / 26.7.1, not the 27 upgrade project. Devices already on 27 do not take this CVE; they still need whatever 27.0.1 actually fixes (Apple published no CVE for it).
  2. Push the point release through MDM now. Supervised iPhone/iPad: enforce 26.7.1 as a minimum on the 26 train. Mac: 15.8.1 or 26.7.1. Do not wait for a KEV row. CISA’s SSVC “none” is not a reason to sit on a vendor-reported targeted parser bug.
  3. Treat high-risk users as a separate queue. Executives, journalists, diplomats, and anyone already on a heightened-risk profile should get the build first, and Lockdown Mode should be a conversation — as a general mercenary-spyware control, not because Apple said Lockdown Mode stops this bug (it did not).
  4. Do not hunt IOCs Apple did not publish. There are no hashes, no domains, no process names in the advisory. A CoreGraphics crash after a weird attachment is interesting; it is not a detection signature. If you have an EDR story for iOS, it is MDM compliance and unexpected configuration profiles, not a YARA rule for this CVE.
  5. Do not skip Sonoma / iOS 18 and call them done. They are not in the fix list. Inventory them. If Apple later ships 14.x / 18.x content, that is a material development. Until then, compensating controls are the only honest answer: reduce who can send those devices files, and accelerate hardware that can take a patched train.
  6. Keep yesterday’s perimeter clock. NetScaler CVE-2026-88771 / 88772 are due 30 September, forensic triage Yes, no workaround. SharePoint CVE-2026-65660, WordPress CVE-2026-87902, and MikroTik CVE-2026-67279 were due 28 September. An iPhone parser does not close an ADC.

RWP assessment

Score 8.4.

Highest-leverage development since yesterday’s NetScaler KEV pair is a same-day Apple security point release for a CoreGraphics out-of-bounds write that Apple itself ties to a targeted, sophisticated iOS report, with Meta as the finder, and with the vulnerable estate defined as everything still on iOS 26 / Sequoia / Tahoe. Evidence quality is high for the vulnerability and the patch (Apple CNA + three HT pages + NVD). Evidence quality is only moderate for exploitation: Apple’s “may have been exploited” is real, CISA has not listed KEV, and CISA-ADP SSVC still says none.

It outranks a second day on NetScaler because yesterday already shipped CTX697096, the two KEV rows, and the Wednesday due date; the clock is not a new finding. It outranks Microsoft’s Storm-3168 / JadePuffer Azure write-up because that primary is 25 September — before yesterday’s Daily Top — and Monday’s amplification is secondary coverage, not a new technical record. It outranks the official MCP Python SDK OAuth credential-theft advisory (GHSA-qx49-fqc8-xw99, 28 September, no CVE as of this morning, no in-the-wild claim). It outranks Keio’s ransomware notice: the operator said trains are running; an IT compromise at a railway group is not confirmed OT impact.

What we are not saying: that this is a mass iPhone worm; that WhatsApp delivered it; that iOS 27 needs this CVE’s patch; that Macs were in the reported attack; that CISA has ordered a three-day clock; that a NetScaler in an industrial DMZ, or a railway booking system, is this story.

What we are watching

Sources

Sources

  1. Apple — Security content of iOS 26.7.1 and iPadOS 26.7.1
  2. Apple — Security content of macOS Tahoe 26.7.1
  3. Apple — Security content of macOS Sequoia 15.8.1
  4. Apple — Security releases
  5. NVD — CVE-2026-86950
  6. CVE — CVE-2026-86950
  7. CISA — KEV JSON feed catalog 2026.09.27
  8. CISA — Known Exploited Vulnerabilities Catalog
  9. The Hacker News — Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
  10. SecurityWeek — Apple Patches Meta-Reported Zero-Day
  11. BleepingComputer — Apple patches CoreGraphics zero-day flaw exploited in attacks