Apple patches zero-day used in targeted spyware attacks
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Apple fixed an actively exploited iOS/iPadOS/macOS flaw used in a sophisticated attack against specific targeted individuals via malicious files.
MS-ISAC has issued an advisory covering CVE-2026-86950, a vulnerability affecting Apple's iOS, iPadOS, macOS Sequoia, and macOS Tahoe that allows arbitrary code execution when a maliciously crafted file is processed. Apple states it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS prior to iOS 27, indicating likely use in a targeted spyware-style campaign rather than broad commodity exploitation.
Successful exploitation could allow an attacker to execute arbitrary code, install programs, view/change/delete data, or create new accounts with full privileges, with impact scaled to the privilege level of the compromised user account. Affected systems are those running versions prior to iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Given the targeted, in-the-wild exploitation against specific individuals, this affects government, business, and home users broadly, though the targeted nature suggests high-value individuals are most at risk currently.
Defenders should apply Apple's patches immediately after testing, enforce least-privilege principles, enable anti-exploitation features (SIP, Gatekeeper), maintain application/library/script allowlisting, deploy host-based intrusion detection/prevention, and educate users on risks from untrusted links and attachments given the drive-by compromise vector.
Mentioned in this report
Detection guidance
macOS Safari or WebKit Content Process Spawning Shell or Script Interpreter
Safari or a WebKit content/networking process spawning a shell, osascript, curl or a scripting interpreter, which is typical of post-exploitation after a drive-by browser or WebKit exploit. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: macOS Safari or WebKit Content Process Spawning Shell or Script Interpreter
id: 09229043-bcd9-5bc9-82ef-71303633a9fd
status: experimental
description: Detects Safari or WebKit helper processes spawning a shell, osascript,
curl or a scripting interpreter. After a drive-by exploit of a WebKit or image-parsing
flaw (for example an Apple zero-day triggered by a crafted file on a web page),
attacker code commonly pivots to child processes. Safari and WebContent almost never
launch these legitimately.
references:
- https://www.cisecurity.org/advisory/a-vulnerability-in-apple-products-could-allow-for-arbitrary-code-execution_2026-104
tags:
- attack.initial-access
- attack.t1189
- attack.execution
logsource:
category: process_creation
product: macos
detection:
selection_parent:
ParentImage|endswith:
- /Safari
- com.apple.WebKit.WebContent
- com.apple.WebKit.Networking
- com.apple.WebKit.GPU
selection_child:
Image|endswith:
- /sh
- /bash
- /zsh
- /osascript
- /curl
- /python3
- /python
- /perl
- /ruby
condition: selection_parent and selection_child
falsepositives:
- Web developers running local tooling through Safari extensions or debugging helpers
- Safari extensions or web-app helpers that legitimately shell out
level: high
author: Vorant
macOS Document or Media Handler Spawning Shell or Script Interpreter
Apps that parse untrusted files or links (Messages, Mail, Preview, Quick Look) spawning a shell or scripting interpreter, indicating possible exploitation of a file-parsing vulnerability. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: macOS Document or Media Handler Spawning Shell or Script Interpreter
id: ff138af0-6955-5aea-85dc-b446aaa4b2dd
status: experimental
description: Detects macOS applications and services that process untrusted content
(Messages, Mail, Preview, Quick Look and image/PDF services) spawning a shell, osascript,
curl or a scripting interpreter. This pattern is consistent with arbitrary code
execution after a maliciously crafted file is processed, as described for in-the-wild
Apple zero-days. Generalises on the parent/child relation, not on any specific file.
references:
- https://www.cisecurity.org/advisory/a-vulnerability-in-apple-products-could-allow-for-arbitrary-code-execution_2026-104
tags:
- attack.initial-access
- attack.t1189
- attack.execution
logsource:
category: process_creation
product: macos
detection:
selection_parent:
ParentImage|endswith:
- /Messages
- /Mail
- /Preview
- /quicklookd
- /QuickLookUIService
- /ImageIOXPCService
selection_child:
Image|endswith:
- /sh
- /bash
- /zsh
- /osascript
- /curl
- /python3
- /perl
condition: selection_parent and selection_child
falsepositives:
- Mail rules or Automator and AppleScript workflows that invoke scripts from Mail
- Custom Quick Look or Preview plugins that call helper scripts
level: medium
author: Vorant
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-apple-products-could-allow-for-arbitrary-code-execution_2026-104
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,484 reports from 153 sources, 493 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs