CVE-2026-86950: Apple CoreGraphics Out-of-Bounds Write Leading to RCE
CVE-2026-86950 is an out-of-bounds write vulnerability in Apple’s CoreGraphics framework affecting iOS, iPadOS, and macOS. Processing a maliciously crafted file can lead to arbitrary code execution. Apple is aware of reports indicating in-the-wild exploitation against targeted individuals.
Overview
CVE-2026-86950 is an out-of-bounds write vulnerability in Apple’s CoreGraphics framework. This critical flaw affects iOS, iPadOS, and macOS, allowing arbitrary code execution when processing a maliciously crafted file. Apple has confirmed reports of this vulnerability being exploited in sophisticated, targeted attacks, underscoring the urgency for immediate patching.
Technical Analysis
The vulnerability, tracked as CVE-2026-86950 (CWE-787), stems from insufficient bounds checking within the CoreGraphics component. When a user processes a specially crafted file, this flaw can be triggered, leading to an out-of-bounds write operation. This memory corruption can then be leveraged to achieve arbitrary code execution in the context of the vulnerable application.
- Vulnerability Type: Out-of-bounds Write (CWE-787)
- Affected Products:
- Apple iOS versions prior to
26.7.1 - Apple iPadOS versions prior to
26.7.1 - Apple macOS versions prior to
15.8.1 - Apple macOS versions
26.0through26.7.0
- Apple iOS versions prior to
- Attack Vector: Network (AV:N), User Interaction Required (UI:R). Exploitation occurs when a user processes a maliciously crafted file. This could be via email attachments, malicious websites, or messaging applications.
- Impact: Arbitrary Code Execution (C:H, I:H, A:H). Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the exploited application.
- CVSS 3.1 Score: 8.8 (High) –
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Detection
Detecting the initial trigger of this vulnerability (processing a malicious file) can be challenging without specific file hashes or content signatures. Detection efforts should focus on post-exploitation activities, such as unusual process creation or network connections originating from applications that typically handle user-supplied content.
- Process Monitoring: Monitor for suspicious child processes spawned by applications like
Safari,Mail,Messages,Preview, or other image/document viewers. Look for shell processes (sh,bash,zsh), scripting interpreters (python,perl,ruby), or network utilities (curl,wget) originating from these parent processes. - Network Activity: Monitor for outbound network connections from typically sandboxed or user-facing applications to unusual external IP addresses or domains.
- File System Monitoring: Look for creation of suspicious files in temporary directories or user home directories by applications that do not typically write executable content.
- Endpoint Telemetry: Analyze EDR logs for process execution anomalies, especially those involving
CoreGraphicsor related libraries.
Sigma Detection Rules
macOS Suspicious Shell Spawn from Apple App
title: macOS Suspicious Shell Spawn from Apple App
id: 8e9f0c1a-2b3d-4e5f-6a7b-8c9d0e1f2a3b
status: experimental
description: Detects shell processes (sh, bash, zsh) spawned by common Apple applications that handle user-supplied content. This could indicate post-exploitation activity following a client-side vulnerability like CVE-2026-86950.
logsource:
product: macos
category: process_creation
detection:
selection_parent:
ParentImage|contains:
- '/Applications/Safari.app/'
- '/Applications/Mail.app/'
- '/Applications/Messages.app/'
- '/Applications/Preview.app/'
- '/Applications/TextEdit.app/'
- '/Applications/Pages.app/'
- '/Applications/Numbers.app/'
- '/Applications/Keynote.app/'
selection_child:
Image|endswith:
- '/bin/sh'
- '/bin/bash'
- '/bin/zsh'
condition: all of selection_*
level: high
Mitigations
- Patch Immediately: Apply the latest security updates for all affected Apple devices.
- Update iOS and iPadOS to version
26.7.1or later. - Update macOS Sequoia to version
15.8.1or later. - Update macOS Tahoe to version
26.7.1or later.
- Update iOS and iPadOS to version
- User Awareness Training: Educate users about the risks of opening unsolicited or suspicious files, attachments, and links, even from seemingly trusted sources.
- Endpoint Security: Ensure endpoint detection and response (EDR) solutions are deployed and configured to monitor for anomalous process behavior and network connections.
- Application Sandboxing: Leverage built-in application sandboxing features where possible to limit the impact of successful exploitation.
- Network Segmentation: Implement network segmentation to restrict outbound communication from user endpoints, limiting potential command-and-control (C2) channels.
References
- https://support.apple.com/en-us/149226
- https://support.apple.com/en-us/149228
- https://support.apple.com/en-us/149229
- http://seclists.org/fulldisclosure/2026/Sep/89
- http://seclists.org/fulldisclosure/2026/Sep/90
- http://seclists.org/fulldisclosure/2026/Sep/91
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86950
Indicators of Compromise
No public IOCs available at time of writing.
MITRE ATT&CK
Generated by
gemini-2.5-flash ·2,000 input / 1,611 output tokens ·
Reviewed and approved by a human analyst before publication