CoreGraphics memory confusion in Apple iOS 26, iPadOS, macOS 26, macOS 15
CoreGraphics memory confusion flaw in Apple iOS 26, iPadOS, macOS 26, and macOS 15. CVSS 8.8 high. Apple reports possible exploitation in targeted attacks.
- Vendor
- Apple
- Product
- iOS 26, iPadOS, macOS 26, macOS 15
- CVSS
- 8.8
- EPSS (exploit probability)
- N/A
- Status
- exploited-in-wild
- Published
Apple released patches for CVE-2026-86950 on September 28, 2026. The vulnerability is in CoreGraphics. Affected builds: iOS 26, iPadOS, macOS 26, macOS 15.
Apple’s advisory stated it “may have been exploited in targeted attacks.” No independent third-party confirmation of exploitation was publicly available at time of publication. The flaw is not on CISA’s Known Exploited Vulnerabilities catalog as of September 29.
CVSS 8.8 (high). Patches available through Apple’s standard update channels. Full details: NVD entry, Apple advisory coverage.
