VORANT. Threat Intelligence Research Sign in Create a free account

Apple patches actively exploited iOS/macOS zero-day

elevated vulnerability technology

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Apple issued emergency patches for CVE-2026-86950, an actively exploited vulnerability affecting iOS 26, macOS 26 and macOS 15, used in targeted attacks against specific individuals.

Apple released security updates addressing CVE-2026-86950, a vulnerability affecting older OS branches: iOS 26, macOS 26, and macOS 15. The current "27" branch (iOS 27/macOS 27) is not affected by this security issue, though it received an unrelated functional update fixing bugs from its release two weeks prior. Apple credits Meta Product Security with reporting the flaw and states it is aware of a report that the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals" on versions of iOS before iOS 27.

The targeted nature of the exploitation and the sourcing from Meta Product Security suggest this may be related to spyware or surveillance-tooling activity, consistent with prior Apple zero-day disclosures affecting a small number of high-value targets rather than broad populations. Defenders supporting users on iOS 26, macOS 26, or macOS 15 should prioritize applying Apple's emergency patch. Devices already updated to the 27 branch are not affected by the security issue, though a follow-up 27.1 release is anticipated to add support for a new foldable iPhone model and may include further changes.

No technical details of the vulnerability, exploitation chain, or IOCs were disclosed in this brief advisory. Organizations with users who may be targets of sophisticated, individually-targeted surveillance (journalists, activists, executives, government personnel) should treat this as a priority patch and consider reviewing device integrity where compromise is suspected.

Mentioned in this report

Vulnerabilities CVE-2026-86950

Source reporting: https://isc.sans.edu/diary/rss/33376

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,196 reports from 149 sources, 2,698 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs