HIGHvulnerability·

CVE-2026-86950: Apple CoreGraphics Out-of-Bounds Write Leading to RCE

CVE-2026-86950 is an out-of-bounds write vulnerability in Apple’s CoreGraphics framework affecting iOS, iPadOS, and macOS. Processing a maliciously crafted file can lead to arbitrary code execution. Apple is aware of reports indicating in-the-wild exploitation against targeted individuals.

This report was researched and drafted by an AI agent and reviewed by a human analyst prior to publication. View the agent workflow →

Overview

CVE-2026-86950 is an out-of-bounds write vulnerability in Apple’s CoreGraphics framework. This critical flaw affects iOS, iPadOS, and macOS, allowing arbitrary code execution when processing a maliciously crafted file. Apple has confirmed reports of this vulnerability being exploited in sophisticated, targeted attacks, underscoring the urgency for immediate patching.

Technical Analysis

The vulnerability, tracked as CVE-2026-86950 (CWE-787), stems from insufficient bounds checking within the CoreGraphics component. When a user processes a specially crafted file, this flaw can be triggered, leading to an out-of-bounds write operation. This memory corruption can then be leveraged to achieve arbitrary code execution in the context of the vulnerable application.

  • Vulnerability Type: Out-of-bounds Write (CWE-787)
  • Affected Products:
    • Apple iOS versions prior to 26.7.1
    • Apple iPadOS versions prior to 26.7.1
    • Apple macOS versions prior to 15.8.1
    • Apple macOS versions 26.0 through 26.7.0
  • Attack Vector: Network (AV:N), User Interaction Required (UI:R). Exploitation occurs when a user processes a maliciously crafted file. This could be via email attachments, malicious websites, or messaging applications.
  • Impact: Arbitrary Code Execution (C:H, I:H, A:H). Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the exploited application.
  • CVSS 3.1 Score: 8.8 (High) – CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Detection

Detecting the initial trigger of this vulnerability (processing a malicious file) can be challenging without specific file hashes or content signatures. Detection efforts should focus on post-exploitation activities, such as unusual process creation or network connections originating from applications that typically handle user-supplied content.

  • Process Monitoring: Monitor for suspicious child processes spawned by applications like Safari, Mail, Messages, Preview, or other image/document viewers. Look for shell processes (sh, bash, zsh), scripting interpreters (python, perl, ruby), or network utilities (curl, wget) originating from these parent processes.
  • Network Activity: Monitor for outbound network connections from typically sandboxed or user-facing applications to unusual external IP addresses or domains.
  • File System Monitoring: Look for creation of suspicious files in temporary directories or user home directories by applications that do not typically write executable content.
  • Endpoint Telemetry: Analyze EDR logs for process execution anomalies, especially those involving CoreGraphics or related libraries.

Sigma Detection Rules

⚠️ AI-generated detection rules. These are experimental starting points. Review field names, EventIDs, and logic against your environment’s schema before deploying. Tune to reduce false positives.

macOS Suspicious Shell Spawn from Apple App

title: macOS Suspicious Shell Spawn from Apple App
id: 8e9f0c1a-2b3d-4e5f-6a7b-8c9d0e1f2a3b
status: experimental
description: Detects shell processes (sh, bash, zsh) spawned by common Apple applications that handle user-supplied content. This could indicate post-exploitation activity following a client-side vulnerability like CVE-2026-86950.
logsource:
  product: macos
  category: process_creation
detection:
  selection_parent:
    ParentImage|contains:
      - '/Applications/Safari.app/'
      - '/Applications/Mail.app/'
      - '/Applications/Messages.app/'
      - '/Applications/Preview.app/'
      - '/Applications/TextEdit.app/'
      - '/Applications/Pages.app/'
      - '/Applications/Numbers.app/'
      - '/Applications/Keynote.app/'
  selection_child:
    Image|endswith:
      - '/bin/sh'
      - '/bin/bash'
      - '/bin/zsh'
  condition: all of selection_*
level: high

Mitigations

  1. Patch Immediately: Apply the latest security updates for all affected Apple devices.
    • Update iOS and iPadOS to version 26.7.1 or later.
    • Update macOS Sequoia to version 15.8.1 or later.
    • Update macOS Tahoe to version 26.7.1 or later.
  2. User Awareness Training: Educate users about the risks of opening unsolicited or suspicious files, attachments, and links, even from seemingly trusted sources.
  3. Endpoint Security: Ensure endpoint detection and response (EDR) solutions are deployed and configured to monitor for anomalous process behavior and network connections.
  4. Application Sandboxing: Leverage built-in application sandboxing features where possible to limit the impact of successful exploitation.
  5. Network Segmentation: Implement network segmentation to restrict outbound communication from user endpoints, limiting potential command-and-control (C2) channels.

References

  • https://support.apple.com/en-us/149226
  • https://support.apple.com/en-us/149228
  • https://support.apple.com/en-us/149229
  • http://seclists.org/fulldisclosure/2026/Sep/89
  • http://seclists.org/fulldisclosure/2026/Sep/90
  • http://seclists.org/fulldisclosure/2026/Sep/91
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86950

Indicators of Compromise

No public IOCs available at time of writing.

MITRE ATT&CK

🤖 AI Attribution
Generated by gemini-2.5-flash ·
2,000 input / 1,611 output tokens ·
Reviewed and approved by a human analyst before publication
#vulnerability#apple#code-execution#high#ios#ipados#macos#vulnerability