macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.
Made by Apple. 6 of its vulnerabilities are known to have been exploited.
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.
CISA added CVE-2026-86950 (Apple Multiple Products) to its Known Exploited Vulnerabilities catalog on September 29, 2026, which means there is reliable evidence of exploitation in the wild. Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
CISA lists this as exploited in the wild. Unpatched macOS and iOS & iPadOS systems are exposed to active attacks now.
Treat this as an emergency.
The latest developments from the last 30 days, newest first.
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
Basis: Reporting by SecurityWeek
UPDATE: severity raised to critical: Apple Multiple Products Out-of-Bounds Write Vulnerability (CVE-2026-86950) is being actively exploited, CISA warns
Basis: CISA Known Exploited Vulnerabilities (government advisory)
Apple Multiple Products Out-of-Bounds Write Vulnerability (CVE-2026-86950) is being actively exploited, CISA warns
Basis: CISA Known Exploited Vulnerabilities (government advisory)
Apple macOS
Apple macOS Improper Authentication Vulnerability
Apple macOS
Apple macOS Use-After-Free Vulnerability
Apple macOS
Apple macOS Out-of-Bounds Write Vulnerability
Apple macOS
Apple macOS Out-of-Bounds Read Vulnerability
Apple macOS
Apple macOS Unspecified Vulnerability
Apple macOS
Apple macOS Unspecified Vulnerability