Apple iOS file parsing RCE exploited (CVE-2026-86950) [PoC]
CVE-2026-86950
CVE-2026-86950: iOS, iPadOS, and macOS memory corruption enables arbitrary code execution from a crafted file. Update to iOS 26.7.1 or macOS 26.7.1 now.
Actively exploited in the wild - CVE-2026-86950 is a high-severity out-of-bounds write in Apple iOS, iPadOS, and macOS that lets an attacker execute arbitrary code by getting a victim to open a maliciously crafted file. Apple says the issue was used in an extremely sophisticated attack against specific targeted individuals running versions of iOS before iOS 27, and fixes are available in iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1.
Overview
CVE-2026-86950 is a memory corruption bug - specifically an out-of-bounds write - in Apple’s file processing code. The software fails to properly check the size of data before writing it into a memory buffer, which is what Apple fixed with improved bounds checking.
In plain terms: when an Apple device opens a specially crafted file, the system writes data past the end of an allocated buffer. An attacker who controls the file’s contents can use that overflow to run their own code with the privileges of the process handling the file. No special privileges or account access are needed on the target device; the only requirement is that the victim opens the malicious file. That covers common delivery paths like email attachments, Messages, AirDrop, shared cloud documents, and files downloaded from a website. This is why user interaction is required but the vulnerability is still rated high (CVSS 8.8).
Impact
Successful exploitation leads to arbitrary code execution on the victim’s device. An attacker could read private data, install malware, or take further actions within the app’s sandbox and beyond, depending on the process that parses the file. Apple’s own advisory confirms the issue may have been exploited in a targeted attack, meaning real-world abuse is confirmed rather than theoretical.
The EPSS score for this CVE sits at just 0.8%, which reflects the narrow, targeted nature of the observed campaign. Broad opportunistic exploitation is unlikely, but for high-risk individuals - journalists, activists, executives, and government staff - the risk is concrete and current.
Remediation
- Update to iOS 26.7.1 or iPadOS 26.7.1 on all iPhones and iPads.
- Update macOS Sequoia to 15.8.1 and macOS Tahoe to 26.7.1.
- Prioritize patching for anyone in a targeted-individual risk profile, along with their immediate contacts and family.
- Until devices are patched, avoid opening unexpected or unsolicited files from email, Messages, or AirDrop.
- Treat this as a same-day patch for high-value targets; there is no configuration workaround, since the flaw lives in core file processing.
Security Insight
This incident fits a pattern Apple has faced repeatedly: zero-days that require only a crafted file and a moment of user curiosity, delivered quietly to a small set of targets rather than the mass market. It echoes the 2025 iOS bug that let the FBI recover deleted Signal messages, another case where Apple’s file and media handling became the entry point. What stands out is the narrow disclosure - exploitation “before iOS 27” against specific individuals - which suggests a well-resourced actor holding a chain rather than commodity malware. For defenders, it is a reminder that Apple’s polished user experience still rests on a large native attack surface, and that targeted campaigns rarely wait for a major OS release to strike.
Related reading:
- Apple fixes iOS CoreGraphics zero-day CVE-2026-86950
- iOS Bug Let FBI Recover Deleted Signal Messages
- LangChain, LangGraph Flaws Expose Files, Secrets,
- Apple Film Group Ransomware Attack by Lamashtu (Apr 2026)
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| DeAurity/CVE-2026-86950-POC Out-of-bounds Write (CWE-787) | ★ 2 |
Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process memory....
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)...
Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)...
Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: H...