The Exploit Bulletin

Archives
Log in
Subscribe
September 29, 2026

The Exploit Bulletin — Tuesday, September 29, 2026: 1 issue requires action

Tuesday, September 29, 2026 — 1 issue requires action. If you run none of the software below, you are done.

Affects: Apple iOS and iPadOS / iPad Pro / macOS


1. CoreGraphics out-of-bounds write via malicious file gives code execution on iOS and macOS (CVE-2026-86950)

REMOTE CODE EXECUTION · HIGH · CVSS 8.8

Apple shipped emergency fixes on 2026-09-28 alongside confirmation the bug was already used against targeted individuals, so fleets left on iOS/iPadOS 26.7, macOS 15.8 or macOS 26.7 remain open to a file-delivered code-execution exploit that an attacker already holds.

An out-of-bounds write in Apple's CoreGraphics component lets a maliciously crafted file trigger arbitrary code execution when it is processed on iOS/iPadOS 26, macOS Sequoia 15 and macOS Tahoe 26. Apple credits the report to Meta Product Security and says the flaw was used against specific targeted individuals running iOS versions before iOS 27.

Affected: Apple iOS and iPadOS < 26.7.1 (iPhone 11 and later; iPad Pro 12.9-inch 3rd gen and later, iPad Pro 11-inch 1st gen and later, iPad Air 3rd gen and later, iPad 8th gen and later, iPad mini 5th gen and later); Apple macOS Sequoia < 15.8.1; Apple macOS Tahoe < 26.7.1

How to Test: Check the OS version on each device or in your MDM inventory: any iPhone/iPad on iOS or iPadOS 26.x below 26.7.1, any Mac on macOS Sequoia 15.x below 15.8.1, or any Mac on macOS Tahoe 26.x below 26.7.1 is affected; per SANS ISC, iOS 27 and macOS 27 are not affected. Apple has published no indicators of compromise; for users likely to be individually targeted, treat unexplained crashes or reboots when opening received files or images as worth investigating.

How to Patch: Update to iOS 26.7.1 / iPadOS 26.7.1, macOS Sequoia 15.8.1, or macOS Tahoe 26.7.1 via Software Update or by pushing the update through MDM; devices already on iOS 27 / macOS 27 need no action for this CVE.

Evidence: VulnCheck KEV · SANS ISC: vulnerability is already being exploited · SecurityWeek: Meta-reported zero-day linked to extremely sophisticated attack

Full entry with sources →


Read on the web · Every past edition

The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.

Spot an error, or an exploit we missed? Reply here or email [email protected].

Don't miss what's next. Subscribe to The Exploit Bulletin:
← Newer The Exploit Bulletin — Wednesday, September 30, 2026: 1 issue requires action Older → The Exploit Bulletin — Monday, September 28, 2026: 1 issue requires action
www.exploitbulletin.com
jbac.co
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.