TL;DR
On September 29, 2026, Apple issued emergency updates to remediate an actively exploited Apple zero-day vulnerability. The critical flaw allows attackers to execute arbitrary code by tricking devices into parsing malicious files. Threat actors have already targeted specific users in the wild, so administrators must update their devices immediately.
- CVE: CVE-2026-86950
- CVSS: 8.8 (High · CVSSv3)
- Product: Apple iOS and iPadOS
- Affected: < 26.7.1, < 15.8.1
- Impact: CWE-787
- Status: Exploited in the wild
- Patched in: 26.7.1, 15.8.1
- Action: Update to 26.7.1, 15.8.1 now
Track every Apple CVE the moment it's exploited.
Get free email alertsWhy It Matters
Industry estimates indicate that over one billion active Apple devices operate worldwide. Consequently, an unpatched vulnerability in core system components introduces severe risk for enterprise and personal data. Apple confirmed that attackers are actively exploiting this Apple zero-day vulnerability in the wild. Specifically, threat groups targeted individual users running software builds released prior to iOS 27. In the official advisory, Apple warned, “Processing a maliciously crafted file may lead to arbitrary code execution.” While attackers have weaponized the flaw in targeted attacks, researchers have confirmed no public proof-of-concept exploit code exists yet. However, unpatched devices remain vulnerable to complete system takeover.
How The Attack Works
The security defect stems from an out-of-bounds write during memory handling. Attackers trigger the flaw by sending a specially crafted document, image, or media file to a target. When an application processes the untrusted file, the parsing engine writes data beyond allocated memory limits. In the advisory, Apple noted that “An out-of-bounds write issue was addressed with improved bounds checking.” This memory corruption enables an attacker to hijack control flow. As a result, the attacker gains arbitrary code execution with the permissions of the vulnerable process.
Affected Versions
This vulnerability affects multiple Apple operating systems across mobile and desktop devices. Specifically, it impacts versions of iOS and iPadOS before version 26.7.1. In addition, the flaw affects macOS Sequoia before 15.8.1 and macOS Tahoe prior to 26.7.1.
Patch Or Mitigation Steps
Administrators and end users must install vendor security patches without delay. You can update mobile devices by downloading the latest iOS and iPadOS security update. For desktop environments, install the fixes provided in the macOS Tahoe security advisory. Users running earlier operating systems should review the macOS Sequoia update details to secure their endpoints. Furthermore, avoid opening unexpected files received from unknown senders. Prompt patching eliminates exposure to this active Apple zero-day vulnerability.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!