High 8.8 Actively Exploited

Apple iOS file parsing RCE exploited (CVE-2026-86950) [PoC]

CVE-2026-86950

By Yazoul AI · automated

CVE-2026-86950: iOS, iPadOS, and macOS memory corruption enables arbitrary code execution from a crafted file. Update to iOS 26.7.1 or macOS 26.7.1 now.

Affected: Apple Ipados Apple Iphone Os Apple Macos

Actively exploited in the wild - CVE-2026-86950 is a high-severity out-of-bounds write in Apple iOS, iPadOS, and macOS that lets an attacker execute arbitrary code by getting a victim to open a maliciously crafted file. Apple says the issue was used in an extremely sophisticated attack against specific targeted individuals running versions of iOS before iOS 27, and fixes are available in iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1.

Overview

CVE-2026-86950 is a memory corruption bug - specifically an out-of-bounds write - in Apple’s file processing code. The software fails to properly check the size of data before writing it into a memory buffer, which is what Apple fixed with improved bounds checking.

In plain terms: when an Apple device opens a specially crafted file, the system writes data past the end of an allocated buffer. An attacker who controls the file’s contents can use that overflow to run their own code with the privileges of the process handling the file. No special privileges or account access are needed on the target device; the only requirement is that the victim opens the malicious file. That covers common delivery paths like email attachments, Messages, AirDrop, shared cloud documents, and files downloaded from a website. This is why user interaction is required but the vulnerability is still rated high (CVSS 8.8).

Impact

Successful exploitation leads to arbitrary code execution on the victim’s device. An attacker could read private data, install malware, or take further actions within the app’s sandbox and beyond, depending on the process that parses the file. Apple’s own advisory confirms the issue may have been exploited in a targeted attack, meaning real-world abuse is confirmed rather than theoretical.

The EPSS score for this CVE sits at just 0.8%, which reflects the narrow, targeted nature of the observed campaign. Broad opportunistic exploitation is unlikely, but for high-risk individuals - journalists, activists, executives, and government staff - the risk is concrete and current.

Remediation

  • Update to iOS 26.7.1 or iPadOS 26.7.1 on all iPhones and iPads.
  • Update macOS Sequoia to 15.8.1 and macOS Tahoe to 26.7.1.
  • Prioritize patching for anyone in a targeted-individual risk profile, along with their immediate contacts and family.
  • Until devices are patched, avoid opening unexpected or unsolicited files from email, Messages, or AirDrop.
  • Treat this as a same-day patch for high-value targets; there is no configuration workaround, since the flaw lives in core file processing.

Security Insight

This incident fits a pattern Apple has faced repeatedly: zero-days that require only a crafted file and a moment of user curiosity, delivered quietly to a small set of targets rather than the mass market. It echoes the 2025 iOS bug that let the FBI recover deleted Signal messages, another case where Apple’s file and media handling became the entry point. What stands out is the narrow disclosure - exploitation “before iOS 27” against specific individuals - which suggests a well-resourced actor holding a chain rather than commodity malware. For defenders, it is a reminder that Apple’s polished user experience still rests on a large native attack surface, and that targeted campaigns rarely wait for a major OS release to strike.

Related reading:

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Public PoC References

Unverified third-party code

These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).

Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.

Repository Stars
DeAurity/CVE-2026-86950-POC

Out-of-bounds Write (CWE-787)

★ 2

Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.

Related Advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.