Apple disclosed and addressed a vulnerability affecting older versions of iOS, iPadOS, and macOS that could allow arbitrary code execution when processing a maliciously crafted file. Apple stated that it is aware of a report indicating that the vulnerability is sophisticated and specifically targeted. Earlier in February, Apple addressed a memory corruption issue in Apple’s dyld component (CVE-2026-20700) that it said had been weaponized in sophisticated cyber-attacks. This was already mentioned in a report (RD202600019).
The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write vulnerability (CWE-787) affecting Apple's CoreGraphics component. If exploited, it could lead to arbitrary code execution when a target processes a maliciously crafted file. Apple addressed the issue with improved bounds checking and attributed its discovery to Meta Product Security. Apple has also acknowledged a report of it being used in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. No CVSS score has been publicly disclosed for this CVE.
Apply vendor-recommended patches and mitigations in accordance with vendor instructions, ensuring alignment with NCSA’s Qatar National Vulnerability Management Guidelines, Version 1.0 including its risk-based prioritization and Reference SLA Matrix. Stakeholders are responsible for evaluating the affected asset’s criticality and internet exposure, prioritizing remediation accordingly, and ensuring that vulnerabilities are remediated within the applicable NCSA timeframe. Where immediate remediation is not feasible, the vulnerability should be formally tracked and managed through the organization’s vulnerability and risk management process until remediation is completed.
We use cookies to enhance your experience on our website. Click 'Accept All' to consent.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
