# Apple patches zero-day used in targeted spyware attacks

Published: 2026-09-30 · Severity: high · Sectors: government-national
Canonical: https://vorant.io/reports/01831c1b-b0b4-5ddc-aaa6-226be1266cc5/apple-patches-zero-day-used-in-targeted-spyware-attacks

> Apple fixed an actively exploited iOS/iPadOS/macOS flaw used in a sophisticated attack against specific targeted individuals via malicious files.

MS-ISAC has issued an advisory covering CVE-2026-86950, a vulnerability affecting Apple's iOS, iPadOS, macOS Sequoia, and macOS Tahoe that allows arbitrary code execution when a maliciously crafted file is processed. Apple states it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS prior to iOS 27, indicating likely use in a targeted spyware-style campaign rather than broad commodity exploitation.

Successful exploitation could allow an attacker to execute arbitrary code, install programs, view/change/delete data, or create new accounts with full privileges, with impact scaled to the privilege level of the compromised user account. Affected systems are those running versions prior to iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Given the targeted, in-the-wild exploitation against specific individuals, this affects government, business, and home users broadly, though the targeted nature suggests high-value individuals are most at risk currently.

Defenders should apply Apple's patches immediately after testing, enforce least-privilege principles, enable anti-exploitation features (SIP, Gatekeeper), maintain application/library/script allowlisting, deploy host-based intrusion detection/prevention, and educate users on risks from untrusted links and attachments given the drive-by compromise vector.

## Mentioned in this report

- Vulnerabilities: CVE-2026-86950 (KEV)

## Detection guidance (public sample)

### macOS Safari or WebKit Content Process Spawning Shell or Script Interpreter

ATT&CK: T1189

Safari or a WebKit content/networking process spawning a shell, osascript, curl or a scripting interpreter, which is typical of post-exploitation after a drive-by browser or WebKit exploit. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: macOS Safari or WebKit Content Process Spawning Shell or Script Interpreter
id: 09229043-bcd9-5bc9-82ef-71303633a9fd
status: experimental
description: Detects Safari or WebKit helper processes spawning a shell, osascript,
  curl or a scripting interpreter. After a drive-by exploit of a WebKit or image-parsing
  flaw (for example an Apple zero-day triggered by a crafted file on a web page),
  attacker code commonly pivots to child processes. Safari and WebContent almost never
  launch these legitimately.
references:
- https://www.cisecurity.org/advisory/a-vulnerability-in-apple-products-could-allow-for-arbitrary-code-execution_2026-104
tags:
- attack.initial-access
- attack.t1189
- attack.execution
logsource:
  category: process_creation
  product: macos
detection:
  selection_parent:
    ParentImage|endswith:
    - /Safari
    - com.apple.WebKit.WebContent
    - com.apple.WebKit.Networking
    - com.apple.WebKit.GPU
  selection_child:
    Image|endswith:
    - /sh
    - /bash
    - /zsh
    - /osascript
    - /curl
    - /python3
    - /python
    - /perl
    - /ruby
  condition: selection_parent and selection_child
falsepositives:
- Web developers running local tooling through Safari extensions or debugging helpers
- Safari extensions or web-app helpers that legitimately shell out
level: high
author: Vorant
```

### macOS Document or Media Handler Spawning Shell or Script Interpreter

ATT&CK: T1189

Apps that parse untrusted files or links (Messages, Mail, Preview, Quick Look) spawning a shell or scripting interpreter, indicating possible exploitation of a file-parsing vulnerability. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: macOS Document or Media Handler Spawning Shell or Script Interpreter
id: ff138af0-6955-5aea-85dc-b446aaa4b2dd
status: experimental
description: Detects macOS applications and services that process untrusted content
  (Messages, Mail, Preview, Quick Look and image/PDF services) spawning a shell, osascript,
  curl or a scripting interpreter. This pattern is consistent with arbitrary code
  execution after a maliciously crafted file is processed, as described for in-the-wild
  Apple zero-days. Generalises on the parent/child relation, not on any specific file.
references:
- https://www.cisecurity.org/advisory/a-vulnerability-in-apple-products-could-allow-for-arbitrary-code-execution_2026-104
tags:
- attack.initial-access
- attack.t1189
- attack.execution
logsource:
  category: process_creation
  product: macos
detection:
  selection_parent:
    ParentImage|endswith:
    - /Messages
    - /Mail
    - /Preview
    - /quicklookd
    - /QuickLookUIService
    - /ImageIOXPCService
  selection_child:
    Image|endswith:
    - /sh
    - /bash
    - /zsh
    - /osascript
    - /curl
    - /python3
    - /perl
  condition: selection_parent and selection_child
falsepositives:
- Mail rules or Automator and AppleScript workflows that invoke scripts from Mail
- Custom Quick Look or Preview plugins that call helper scripts
level: medium
author: Vorant
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-apple-products-could-allow-for-arbitrary-code-execution_2026-104

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/01831c1b-b0b4-5ddc-aaa6-226be1266cc5/apple-patches-zero-day-used-in-targeted-spyware-attacks.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
