CISA lists exploited Apple CoreGraphics flaw; iOS and macOS fixes available
CISA added CVE-2026-86950 to its exploited-vulnerability catalog. Apple has released fixes for supported iOS, iPadOS, and macOS versions and describes reports of highly targeted attacks.
CISA added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog on September 29. The flaw is an out-of-bounds write in Apple's CoreGraphics component; processing a maliciously crafted file may lead to arbitrary code execution. Apple has released security updates for iPhone, iPad, and Mac versions covered by its advisories. This is a patch-now signal, but it is not evidence of broad, indiscriminate attacks on every Apple device.
What CISA and Apple actually say
CISA's catalog classifies the vulnerability as known exploited and lists Apple iOS, iPadOS, and macOS among affected products. Its entry gives October 2 as the remediation due date under the applicable federal directive. That date is for covered US federal agencies, not a universal consumer deadline. Other organizations should follow their own risk-based patching process and Apple's vendor instructions.
Apple's language is narrower than a claim of widespread exploitation. The company says it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. Apple attributes the CVE to Meta Product Security and says improved bounds checking addresses the out-of-bounds write. CISA's KEV designation and Apple's cautious description should both be preserved when discussing the threat.
Which updates carry the fix
Apple's advisory lists iOS 26.7.1 and iPadOS 26.7.1 for supported iPhone and iPad models. Separate advisories list macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Check the update offered to each device rather than assuming one version number applies to every supported product. Apple's iOS and iPadOS advisory names iPhone 11 and later, plus specified iPad Pro, iPad Air, standard iPad, and iPad mini generations.
For a personal device, open the operating system's Software Update screen and install the applicable Apple security release. For managed fleets, confirm which affected devices have received the fixed builds and prioritize systems exposed to untrusted files. The advisories describe the impact and fixes; they do not provide evidence that any particular reader has been compromised.
How to interpret the deadline
The useful distinction is between patch availability, evidence of exploitation, and who faces a formal deadline. Apple published the fixes on September 28, CISA added the CVE to KEV on September 29, and CISA's October 2 date is a directive-driven remediation date for covered agencies. If a device cannot be updated immediately, consult Apple's current guidance and your organization's security team rather than treating this article as a substitute for device-specific advice.
Sources
Try the related loot
GoDrop: Give Coding Agents a Shareable File URL
