{"id":"CVE-2026-86950","url":"https://www.cyber-defence.io/tools/cve/CVE-2026-86950","generatedAt":"2026-10-02T15:52:32.000Z","title":"Apple Multiple Products Out-of-Bounds Write Vulnerability","description":"An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.","published":"2026-09-28T20:17:11.000Z","lastModified":"2026-10-01T18:17:28.000Z","status":"Analyzed","sourceIdentifier":"product-security@apple.com","cvss":{"version":"3.1","score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"cwe":["CWE-787"],"affected":["apple/ipados","apple/iphone os","apple/macos"],"epss":{"score":0.01242,"percentile":0.68097,"date":"2026-10-01","history":[{"date":"2026-09-29","score":0.00812,"percentile":0.55295}]},"kev":{"listed":true,"dateAdded":"2026-09-29","dueDate":"2026-10-02","knownRansomwareCampaignUse":"Unknown","notes":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.\nhttps://support.apple.com/en-us/149226 ; https://support.apple.com/en-us/149228 ; https://support.apple.com/en-us/149229 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-86950"},"exploits":{"count":0,"verified":false,"firstPublished":null,"source":"Exploit-DB (https://gitlab.com/exploit-database/exploitdb)","entries":[]},"verdict":{"level":"urgent","text":"Known to be exploited in the wild (CISA KEV, CISA remediation deadline 2 October 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise."},"changes":[{"kind":"kev","label":"Added to KEV","at":"2026-09-29T00:00:00.000Z","detail":{"name":"Apple Multiple Products Out-of-Bounds Write Vulnerability","vendor":"Apple","dueDate":"2026-10-02","product":"Multiple Products","ransomware":"Unknown"},"summary":"Added to CISA KEV — known to be exploited; federal remediation due 2026-10-02."},{"kind":"new","label":"New CVE","at":"2026-09-28T20:17:11.000Z","detail":{"score":"8.8","severity":"HIGH","publishedAt":"2026-09-28T20:17:11.193Z"},"summary":"New CVE, high severity (CVSS 8.8)."}],"references":[{"url":"https://support.apple.com/en-us/149226","tags":["Release Notes","Vendor Advisory"],"source":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/149228","tags":["Release Notes","Vendor Advisory"],"source":"product-security@apple.com"},{"url":"https://support.apple.com/en-us/149229","tags":["Release Notes","Vendor Advisory"],"source":"product-security@apple.com"},{"url":"http://seclists.org/fulldisclosure/2026/Sep/89","tags":["Mailing List","Third Party Advisory"],"source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2026/Sep/90","tags":["Mailing List","Third Party Advisory"],"source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://seclists.org/fulldisclosure/2026/Sep/91","tags":["Mailing List","Third Party Advisory"],"source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-86950","tags":["US Government Resource"],"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"sources":{"nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-86950","epss":"https://www.first.org/epss/","kev":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog","exploitdb":"https://www.exploit-db.com/"},"licence":"CC BY 4.0 — link back to the CVE Explorer if you publish the results; upstream data remains subject to its own terms."}