securityonline.info 29 Sept 2026, 00:21 UTC

Apple Warns of Targeted Attacks Exploiting Critical File Flaw

Apple Warns of Targeted Attacks Exploiting Critical File Flaw
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

APPLE issued emergency security updates on 29 September 2026 for CVE-2026-86950, a high-severity vulnerability reportedly exploited in targeted attacks. The flaw, rated 8.8 under CVSSv3, affects iOS and iPadOS versions before 26.7.1, macOS Tahoe before 26.7.1 and macOS Sequoia before 15.8.1. Apple said that processing a maliciously crafted file could lead to arbitrary code execution.

The report says there is no public proof-of-concept exploit, but Apple has confirmed exploitation in the wild against specific users running earlier software builds.

The vulnerability is described as an out-of-bounds write caused by inadequate memory bounds checking. An attacker could send a specially crafted document, image or media file; when an application parses it, data may be written beyond the allocated memory area. This memory corruption could allow control-flow hijacking and arbitrary code execution with the privileges of the affected process. Users and administrators should install iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1, as applicable. The report also advises avoiding unexpected files from unknown senders until devices are updated.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline