The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
This vulnerability is being actively exploited in the wild, according to the CISA Known Exploited Vulnerabilities catalog.
CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability
- Identifier
- CVE-2026-86950
- Published
- Record updated
Summary
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics. Exploitation may lead to arbitrary code execution. The item is listed as actively exploited in the wild (CISA KEV).
Mitigation
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk and CISA's "Forensics Triage Requirements". Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Due date: 2026-10-02.