CVE-2026-86950

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

CVSS
—
EPSS
—
CISA KEV
Not listed
Exploitation
none
Public exploits
None seen
State
PUBLISHED

Coverage

What we observed

No signals recorded

CVE® is a registered trademark of The MITRE Corporation. CVE Records are reproduced under the CVE Program Terms of Use. CVE Program Terms of Use