Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Apple Multiple Products Out-of-Bounds Write Vulnerability (CVE-2026-86950) is being actively exploited, CISA warns

CISA added CVE-2026-86950 (Apple Multiple Products) to its Known Exploited Vulnerabilities catalog on September 29, 2026, which means there is reliable evidence of exploitation in the wild. Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

Excerpt from the primary source: CISA Known Exploited Vulnerabilities

Who is affected

Home users · Small businesses · Security professionals

Affected technology: iOS & iPadOS, macOS, Multiple Products

Why it matters

CISA lists this as exploited in the wild. Unpatched macOS and iOS & iPadOS systems are exposed to active attacks now.

Automated: stated only from CISA listings and the exploitation evidence in the sources below.

What you should do · Act now

Treat this as an emergency. Identify every system running macOS, iOS & iPadOS and Multiple Products, apply the vendor's fix or published mitigations immediately, and check for signs of compromise. Patching alone does not remove an attacker who already got in.

CISA's required action for CVE-2026-86950: "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines." US federal civilian agencies must comply by October 2, 2026.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Government advisory

Apple Multiple Products Out-of-Bounds Write Vulnerability (CVE-2026-86950) is being actively exploited, CISA warns CISA Known Exploited Vulnerabilities · cisa.gov · Sep 29, 2026 · Primary source

Security research

Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th) SANS Internet Storm Center · isc.sans.edu · Sep 28, 2026

Original reporting

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks The Hacker News · thehackernews.com · Sep 28, 2026

Additional reporting

Apple Zero-Day Vulnerability Weaponized in Targeted Attacks Dark Reading · darkreading.com · Sep 29, 2026
Severity: ElevatedAction: Be aware

Chrome Beta for iOS Update

Hi everyone! We've just released Chrome Beta 156 (156.0.8078.3) for iOS; it'll become available on App Store in the next few days. You can see a partial list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Chrome Release Team Google Chrome…

Severity: ElevatedAction: Be aware

Chrome Stable for iOS Update

Hi everyone! We've just released Chrome Stable 155 (155.0.8059.24) for iOS; it'll become available on App Store in the next few hours. This release includes stability and performance improvements. You can see a full list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Chrome Release Team Google Chrome…