Back Redpacketsecurity CVE Alert: CVE-2026-86950 – Apple
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
**Risk verdict:** High-impact code execution warrants prompt fleet-wide remediation, but the supplied assessment does not mark exploitation as active.
**Why this matters:** A successful attack could let an attacker run code on a victim’s device, potentially enabling data theft, surveillance or further compromise. The reported use against selected individuals raises concern for targeted operations, although the available exploitation assessment records none and does not establish broad campaigns.
**Most likely attack path:** An attacker sends or otherwise makes a malicious file available to a user, who must open or process it; no prior privileges are indicated. The network-reachable, low-complexity path makes delivery feasible, but required user interaction is a meaningful barrier. Scope is unchanged, so lateral movement or access beyond the affected device is not established by these metrics.
**Who is most exposed:** Organisations with large Apple endpoint fleets are most exposed, particularly users who regularly open files from external contacts or handle sensitive information. Managed mobiles and Macs alike should be included in inventory and remediation checks.
Review endpoint telemetry for unusual processes spawned after file opening or previewing.
Investigate suspicious attachments and file-sharing activity preceding unexpected crashes or execution.
Hunt for anomalous outbound connections from affected endpoints after file interaction.
Prioritise reports from high-risk users for incident review.
Mitigation and prioritisation:
Expedite the vendor’s fixed releases across all affected endpoint types; verify installation centrally.
Restrict untrusted file handling and use managed attachment or download controls until patched.
For exposed high-risk users, consider temporary limits on opening files from unknown sources.
Check KEV status and EPSS when available; both are absent here, so urgency cannot be refined from those signals.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
