AllCyberNews

CVE-2026-86950

Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)

CVSS 8.8 high · Apple iOS and iPadOS · published 2026-09-28

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Coverage 1 source

  1. 2026-09-29 Help Net Security critical Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)

    Apple patches actively exploited zero-day in iOS and macOS.

Also covered