Apple Releases Security Updates for macOS, iOS, and iPadOS
CVE-2026-86950 is under active exploitation and could lead to arbitrary code execution
Summary
CVE-2026-86950 is under active exploitation and could lead to arbitrary code execution
Affected platforms
The following platforms are known to be affected:
Threat details
Active exploitation of CVE-2026-86950
Apple have stated that CVE-2026-86950 has been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
The NHS England National CSOC assesses that further exploitation attempts are likely.
Introduction
Apple has released security updates to address an exploited vulnerability in the CoreGraphics element of macOS Sequoia, macOS Tahoe, iOS, and iPadOS.
- CVE-2026-86950 - Out-of-Bounds Write vulnerability that could lead to arbitrary code execution - CVSSv3: 8.8
Remediation advice
Affected organisations are encouraged to review the relevant Apple security releases below and apply the latest updates.
Remediation steps
| Type | Step |
|---|---|
| Patch |
iOS 26.7.1 and iPadOS 26.7.1 https://support.apple.com/en-us/149226 |
| Patch |
Sequoia 15.8.1 https://support.apple.com/en-us/149229 |
| Patch |
Tahoe 26.7.1 https://support.apple.com/en-us/149228 |
Definitive source of threat updates
Last edited: 30 September 2026 1:30 pm