Threat Overview
Apple released emergency updates on September 28, 2026 for CVE-2026-86950, a CoreGraphics out-of-bounds write that can cause arbitrary code execution when a device processes a maliciously crafted file. Apple states it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 27. The fixed releases are iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Apple has not published the delivery vector, malicious file type, exploit-chain details, attacker infrastructure, payload, victim identity, or IOCs. The Sentinel hunt must therefore avoid pretending to identify the exploit itself. It focuses on exposure inventory, security detections, suspicious child processes from Apple file-rendering or user-facing applications, unusual network activity following file handling, persistence created shortly afterward, and crash telemetry where those sources are ingested.
References
- Apple — About the security content of iOS 26.7.1 and iPadOS 26.7.1 — September 28, 2026.
- Apple — About the security content of macOS Tahoe 26.7.1 — September 28, 2026.
- Apple — About the security content of macOS Sequoia 15.8.1 — September 28, 2026.
- Dark Reading — Apple Zero-Day Vulnerability Weaponized in Targeted Attacks — September 29, 2026.
Impacted Systems
- Vendor/component: Apple CoreGraphics file-processing framework.
- Affected products: iPhone and iPad devices on iOS/iPadOS 26 before 26.7.1; Mac systems on macOS Tahoe 26 before 26.7.1; Mac systems on macOS Sequoia 15 before 15.8.1.
- Fixed versions: iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.
- Explicitly useful boundary: Apple says targeted exploitation affected iOS versions before iOS 27. Apple did not claim iOS 27 was vulnerable in the advisory.
- Supported hardware for iOS/iPadOS fix: iPhone 11 and later; iPad Pro 12.9-inch 3rd generation+, iPad Pro 11-inch 1st generation+, iPad Air 3rd generation+, iPad 8th generation+, and iPad mini 5th generation+.
- Prerequisite: Processing a maliciously crafted file; the file format and delivery method are not disclosed.
- Deployment model: Enterprise-managed and personal Apple endpoints. Sentinel visibility depends on MDE, MDM/Intune, security alerts, or forwarded macOS logs.
Why this matters
Apple has acknowledged targeted exploitation with potential arbitrary code execution. Executive, legal, government, research, and other high-risk users often use Apple devices that may have less SOC telemetry than Windows endpoints. The absence of public IOCs makes patch compliance and post-file-processing behaviors more important than IOC matching.
Exploitation Status
Apple confirms a report of possible exploitation in an extremely sophisticated attack against specific targeted individuals. That vendor statement is the reliable exploitation basis. No public campaign attribution, payload, exploit sample, delivery file, infrastructure, or customer-impact count is available. The behavioral hunts below are researcher-informed defensive hypotheses and must not be treated as signatures for CVE-2026-86950.
What this hunt looks for
Macs below the fixed releases, Apple or CoreGraphics security alerts, file-rendering applications spawning shells or interpreters, new destinations after file processing, process-to-network sequences, LaunchAgent or LaunchDaemon persistence, and CoreGraphics-related crash signals.
Required logs
Microsoft Defender for Endpoint DeviceInfo, DeviceProcessEvents, DeviceNetworkEvents, and DeviceFileEvents for onboarded Macs; Microsoft security alerts; forwarded macOS crash logs in Syslog where available; and authoritative MDM or Intune inventory for iPhone and iPad patch status.
Hunt 1 — macOS devices on affected release branches below fixed versions
DeviceInfo
| where TimeGenerated > ago(7d)
| where OSPlatform =~ "macOS"
| summarize arg_max(TimeGenerated,*) by DeviceId
| extend ParsedVersion=parse_version(OSVersion)
| where (ParsedVersion >= parse_version("15.0") and ParsedVersion < parse_version("15.8.1")) or (ParsedVersion >= parse_version("26.0") and ParsedVersion < parse_version("26.7.1"))
| project TimeGenerated,DeviceName,DeviceId,OSPlatform,OSVersion,OSBuild,MachineGroup,OnboardingStatus
| order by OSVersion asc
Hunt 2 — Apple or CoreGraphics exploit-related security alerts
SecurityAlert
| where TimeGenerated > ago(30d)
| where ProductName has_any ("Microsoft Defender for Endpoint","Microsoft Defender XDR")
| where AlertName has_any ("Apple","macOS","CoreGraphics","exploit","memory corruption") or Description has_any ("CVE-2026-86950","CoreGraphics","out-of-bounds write")
| summarize arg_max(TimeGenerated,*) by SystemAlertId
| project TimeGenerated,AlertName,AlertSeverity,CompromisedEntity,Description,ProviderName,ProductName,SystemAlertId
| order by TimeGenerated desc
Hunt 3 — File-rendering or user-facing macOS applications spawning shells or interpreters
DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName in~ ("Preview","QuickLookUIService","QuickLookSatellite","Safari","Mail","Finder")
| where FileName in~ ("sh","bash","zsh","osascript","python","python3","curl","wget")
| project TimeGenerated,DeviceName,AccountName,InitiatingProcessFileName,InitiatingProcessCommandLine,FileName,ProcessCommandLine,SHA256
| order by TimeGenerated desc
Hunt 4 — Newly observed destinations contacted by Apple file-processing applications
let Baseline=DeviceNetworkEvents
| where TimeGenerated between (ago(30d)..ago(1d))
| where InitiatingProcessFileName in~ ("Preview","QuickLookUIService","QuickLookSatellite","Safari","Mail","Finder")
| summarize by DeviceId,RemoteUrl,RemoteIP;
DeviceNetworkEvents
| where TimeGenerated > ago(1d) and ActionType == "ConnectionSuccess"
| where InitiatingProcessFileName in~ ("Preview","QuickLookUIService","QuickLookSatellite","Safari","Mail","Finder")
| join kind=leftanti Baseline on DeviceId,RemoteUrl,RemoteIP
| summarize FirstSeen=min(TimeGenerated),LastSeen=max(TimeGenerated),Connections=count(),RemotePorts=make_set(RemotePort,20),Commands=make_set(InitiatingProcessCommandLine,10) by DeviceName,InitiatingProcessFileName,RemoteUrl,RemoteIP
| order by Connections desc
Hunt 5 — Suspicious process followed by network egress on macOS
let SuspectProcesses=DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFileName in~ ("Preview","QuickLookUIService","QuickLookSatellite","Safari","Mail","Finder")
| where FileName in~ ("sh","bash","zsh","osascript","python","python3","curl","wget")
| project DeviceId,DeviceName,ProcessId,ProcessTime=TimeGenerated,Process=FileName,ProcessCommandLine;
DeviceNetworkEvents
| where TimeGenerated > ago(30d) and ActionType == "ConnectionSuccess"
| project DeviceId,ProcessId=InitiatingProcessId,NetworkTime=TimeGenerated,RemoteUrl,RemoteIP,RemotePort
| join kind=inner SuspectProcesses on DeviceId,ProcessId
| where NetworkTime between (ProcessTime..ProcessTime+10m)
| project ProcessTime,NetworkTime,DeviceName,Process,ProcessCommandLine,RemoteUrl,RemoteIP,RemotePort
| order by ProcessTime desc
Hunt 6 — New LaunchAgent or LaunchDaemon persistence after suspicious user-facing activity
DeviceFileEvents
| where TimeGenerated > ago(30d)
| where ActionType in ("FileCreated","FileModified")
| where FolderPath has_any ("/Library/LaunchAgents/","/Library/LaunchDaemons/","/Users/") and FileName endswith ".plist"
| where InitiatingProcessFileName in~ ("Preview","QuickLookUIService","QuickLookSatellite","Safari","Mail","Finder","sh","bash","zsh","osascript","python","python3")
| project TimeGenerated,DeviceName,ActionType,FolderPath,FileName,SHA256,InitiatingProcessAccountName,InitiatingProcessFileName,InitiatingProcessCommandLine
| order by TimeGenerated desc
Hunt 7 — CoreGraphics or rendering-process crash signals in forwarded macOS logs
Syslog
| where TimeGenerated > ago(30d)
| where SyslogMessage has_any ("CoreGraphics","CGImage","ImageIO","Preview","QuickLookUIService","QuickLookSatellite")
| where SyslogMessage has_any ("crash","EXC_BAD_ACCESS","SIGSEGV","segmentation fault","out-of-bounds","ReportCrash")
| project TimeGenerated,Computer,ProcessName,Facility,SeverityLevel,SyslogMessage
| order by TimeGenerated desc
Hunt 8 — Recently downloaded files followed by suspicious macOS child processes
let Downloads=DeviceFileEvents
| where TimeGenerated > ago(30d) and ActionType == "FileCreated"
| where FolderPath has_any ("/Downloads/","/Mail Downloads/","/tmp/","/private/var/folders/")
| project DeviceId,FileTime=TimeGenerated,DownloadedFile=FileName,DownloadedPath=FolderPath,SHA256;
let Children=DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where FileName in~ ("sh","bash","zsh","osascript","python","python3","curl","wget")
| project DeviceId,ProcessTime=TimeGenerated,DeviceName,AccountName,FileName,ProcessCommandLine,InitiatingProcessFileName;
Downloads
| join kind=inner Children on DeviceId
| where ProcessTime between (FileTime..FileTime+10m)
| project FileTime,ProcessTime,DeviceName,AccountName,DownloadedPath,DownloadedFile,SHA256,FileName,ProcessCommandLine,InitiatingProcessFileName
| order by ProcessTime desc
Detection Notes
- Hunt 1 is the most reliable Sentinel action because Apple has not released IOCs. Confirm iOS and iPadOS exposure separately through authoritative MDM inventory.
- Hunts 3 through 8 are behavioral hypotheses, not CVE signatures. Apple has not disclosed the malicious file type, exploit chain, or payload.
- Safari, Mail, Finder, Preview, and Quick Look legitimately handle files and initiate network activity. Child shells, persistence writes, or rare destinations materially raise confidence.
DeviceInfo,DeviceProcessEvents, andDeviceNetworkEventscoverage on macOS depends on MDE onboarding and connector ingestion. Mobile Apple devices are usually not represented in those tables.- Forwarded macOS crash logs are uncommon in Sentinel. If they are not ingested, Hunt 7 will provide no visibility.
- Version comparison assumes standard numeric
OSVersionvalues; verify nonstandard inventory strings manually.