CVE-2026-86950 — IPADOS
HIGHCVE-2026-86950 is a high-severity (CVSS 8.8) Out-of-bounds Write vulnerability in apple ipados. It is in CISA's Known Exploited Vulnerabilities catalog (added 2026-09-29) — treat it as actively exploited and patch now. A fix is available — see the affected versions and patch details below.
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a…
Exploitation Status
Actively exploited in the wild
- Confirmed by CISA's Known Exploited Vulnerabilities catalog on 2026-09-29. Federal agencies were required to remediate by 2026-10-02.
- A successful exploit gives an attacker total control of the affected component, not partial access.
Exploitation and automatability from CISA (KEV catalog and SSVC triage) for CVE-2026-86950.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2026-86950 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 380,526 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Affected Products
ipadosappleiphone osapplemacosappleDetection & mitigation playbook
Vendor / applianceDetect
Inventory every apple ipados deployment and check each version against the affected-products list above.
Fix
Apply the apple ipados security patch or hotfix for CVE-2026-86950 on the affected version, following the vendor advisory for your exact build.
Workarounds
Stop feeding it untrusted input: reject or quarantine files and payloads from unverified sources until you can upgrade, restrict accepted formats to the ones you actually need, and run the parsing or decoding step in a least-privileged sandbox or short-lived worker so a crash or corrupted read cannot reach the rest of the process. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.
Frequently Asked Questions
Is CVE-2026-86950 being exploited in your environment?
Detect and block the exploit chain at execution, on systems you cannot patch yet.