Apple Multiple Products Out-of-Bounds Write Vulnerability (CVE-2026-86950) is being actively exploited, CISA warns
CISA added CVE-2026-86950 (Apple Multiple Products) to its Known Exploited Vulnerabilities catalog on September 29, 2026, which means there is reliable evidence of exploitation in the wild. Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
Excerpt from the primary source: CISA Known Exploited Vulnerabilities
Who is affected
Home users · Small businesses · Security professionals
Affected technology: iOS & iPadOS, macOS, Multiple Products
Why it matters
CISA lists this as exploited in the wild. Unpatched macOS and iOS & iPadOS systems are exposed to active attacks now.
Automated: stated only from CISA listings and the exploitation evidence in the sources below.
What you should do · Act now
Treat this as an emergency. Identify every system running macOS, iOS & iPadOS and Multiple Products, apply the vendor's fix or published mitigations immediately, and check for signs of compromise. Patching alone does not remove an attacker who already got in.
CISA's required action for CVE-2026-86950: "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines." US federal civilian agencies must comply by October 2, 2026.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Government advisory
Security research
Original reporting
Related
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.
Chrome Beta for iOS Update
Hi everyone! We've just released Chrome Beta 156 (156.0.8078.3) for iOS; it'll become available on App Store in the next few days. You can see a partial list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Chrome Release Team Google Chrome…
Chrome Stable for iOS Update
Hi everyone! We've just released Chrome Stable 155 (155.0.8059.24) for iOS; it'll become available on App Store in the next few hours. This release includes stability and performance improvements. You can see a full list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Chrome Release Team Google Chrome…
Mobile malware warning from Ukrainian researchers includes iPhone exploit kit
'Hit and run' iPhone malware known as DarkSword is part of a wave of Russian attacks on iOS and Android devices, according to Ukraine's SSSCIP.
