CVE-2026-86950

KEV
🔴 Łataj teraz

Błąd zapisu poza granicami w systemach Apple może prowadzić do zdalnego wykonania kodu.

CVSS
8.8
EPSS
1.2%
Exploit
weaponized
Vendor
apple
Opis źródłowy (NVD)

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

rce Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS8.8
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)1.2%
Opublikowano (NVD)2026-09-28 20:17:11 UTC
Ostatnia modyfikacja (NVD)2026-10-01 18:17:28 UTC
Referencje