VORANT. Threat Intelligence Research Sign in Create a free account

Apple patches zero-day used in targeted spyware attacks

high vulnerability government-national

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Apple fixed an actively exploited iOS/iPadOS/macOS flaw used in a sophisticated attack against specific targeted individuals via malicious files.

MS-ISAC has issued an advisory covering CVE-2026-86950, a vulnerability affecting Apple's iOS, iPadOS, macOS Sequoia, and macOS Tahoe that allows arbitrary code execution when a maliciously crafted file is processed. Apple states it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS prior to iOS 27, indicating likely use in a targeted spyware-style campaign rather than broad commodity exploitation.

Successful exploitation could allow an attacker to execute arbitrary code, install programs, view/change/delete data, or create new accounts with full privileges, with impact scaled to the privilege level of the compromised user account. Affected systems are those running versions prior to iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Given the targeted, in-the-wild exploitation against specific individuals, this affects government, business, and home users broadly, though the targeted nature suggests high-value individuals are most at risk currently.

Defenders should apply Apple's patches immediately after testing, enforce least-privilege principles, enable anti-exploitation features (SIP, Gatekeeper), maintain application/library/script allowlisting, deploy host-based intrusion detection/prevention, and educate users on risks from untrusted links and attachments given the drive-by compromise vector.

Mentioned in this report

Vulnerabilities CVE-2026-86950KEV

Detection guidance

macOS Safari or WebKit Content Process Spawning Shell or Script Interpreter

ATT&CK T1189

Safari or a WebKit content/networking process spawning a shell, osascript, curl or a scripting interpreter, which is typical of post-exploitation after a drive-by browser or WebKit exploit. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: macOS Safari or WebKit Content Process Spawning Shell or Script Interpreter
id: 09229043-bcd9-5bc9-82ef-71303633a9fd
status: experimental
description: Detects Safari or WebKit helper processes spawning a shell, osascript,
  curl or a scripting interpreter. After a drive-by exploit of a WebKit or image-parsing
  flaw (for example an Apple zero-day triggered by a crafted file on a web page),
  attacker code commonly pivots to child processes. Safari and WebContent almost never
  launch these legitimately.
references:
- https://www.cisecurity.org/advisory/a-vulnerability-in-apple-products-could-allow-for-arbitrary-code-execution_2026-104
tags:
- attack.initial-access
- attack.t1189
- attack.execution
logsource:
  category: process_creation
  product: macos
detection:
  selection_parent:
    ParentImage|endswith:
    - /Safari
    - com.apple.WebKit.WebContent
    - com.apple.WebKit.Networking
    - com.apple.WebKit.GPU
  selection_child:
    Image|endswith:
    - /sh
    - /bash
    - /zsh
    - /osascript
    - /curl
    - /python3
    - /python
    - /perl
    - /ruby
  condition: selection_parent and selection_child
falsepositives:
- Web developers running local tooling through Safari extensions or debugging helpers
- Safari extensions or web-app helpers that legitimately shell out
level: high
author: Vorant

macOS Document or Media Handler Spawning Shell or Script Interpreter

ATT&CK T1189

Apps that parse untrusted files or links (Messages, Mail, Preview, Quick Look) spawning a shell or scripting interpreter, indicating possible exploitation of a file-parsing vulnerability. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: macOS Document or Media Handler Spawning Shell or Script Interpreter
id: ff138af0-6955-5aea-85dc-b446aaa4b2dd
status: experimental
description: Detects macOS applications and services that process untrusted content
  (Messages, Mail, Preview, Quick Look and image/PDF services) spawning a shell, osascript,
  curl or a scripting interpreter. This pattern is consistent with arbitrary code
  execution after a maliciously crafted file is processed, as described for in-the-wild
  Apple zero-days. Generalises on the parent/child relation, not on any specific file.
references:
- https://www.cisecurity.org/advisory/a-vulnerability-in-apple-products-could-allow-for-arbitrary-code-execution_2026-104
tags:
- attack.initial-access
- attack.t1189
- attack.execution
logsource:
  category: process_creation
  product: macos
detection:
  selection_parent:
    ParentImage|endswith:
    - /Messages
    - /Mail
    - /Preview
    - /quicklookd
    - /QuickLookUIService
    - /ImageIOXPCService
  selection_child:
    Image|endswith:
    - /sh
    - /bash
    - /zsh
    - /osascript
    - /curl
    - /python3
    - /perl
  condition: selection_parent and selection_child
falsepositives:
- Mail rules or Automator and AppleScript workflows that invoke scripts from Mail
- Custom Quick Look or Preview plugins that call helper scripts
level: medium
author: Vorant

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-apple-products-could-allow-for-arbitrary-code-execution_2026-104

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,484 reports from 153 sources, 493 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs