Apple Products Remote Code Execution Vulnerability

Imported from official source

Announcement

A vulnerability has been identified in Apple Products. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

CVE-2026-86950 is being exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.  Processing a maliciously crafted file may lead to arbitrary code execution. Hence, the risk level is rated as High Risk.

  • Versions prior to iOS 26.7.1 and iPadOS 26.7.1
  • Before installation of the software, please visit the vendor web-site for more details.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://www.hkcert.org/security-bulletin/apple-products-remote-code-execution-vulnerability_20260929

    Officially imported this from Hong Kong Computer Emergency Response Team Coordination Centre’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Hong Kong Computer Emergency Response Team Coordination Centre — imported from official source
    Official source
    https://www.hkcert.org/getrss/security-bulletin RSS
    Imported
    October 03, 2026 20:41
    Versions
    1 recorded
    Identity
    https://www.hkcert.org/security-bulletin/apple-products-remote-code-execution-vulnerabi...

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.