# Apple patches actively exploited iOS/macOS zero-day

Published: 2026-09-28 · Severity: elevated · Sectors: technology
Canonical: https://vorant.io/reports/eb5dac1c-e593-506e-9834-7ea7a171fa9b/apple-patches-actively-exploited-ios-macos-zero-day

> Apple issued emergency patches for CVE-2026-86950, an actively exploited vulnerability affecting iOS 26, macOS 26 and macOS 15, used in targeted attacks against specific individuals.

Apple released security updates addressing CVE-2026-86950, a vulnerability affecting older OS branches: iOS 26, macOS 26, and macOS 15. The current "27" branch (iOS 27/macOS 27) is not affected by this security issue, though it received an unrelated functional update fixing bugs from its release two weeks prior. Apple credits Meta Product Security with reporting the flaw and states it is aware of a report that the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals" on versions of iOS before iOS 27.

The targeted nature of the exploitation and the sourcing from Meta Product Security suggest this may be related to spyware or surveillance-tooling activity, consistent with prior Apple zero-day disclosures affecting a small number of high-value targets rather than broad populations. Defenders supporting users on iOS 26, macOS 26, or macOS 15 should prioritize applying Apple's emergency patch. Devices already updated to the 27 branch are not affected by the security issue, though a follow-up 27.1 release is anticipated to add support for a new foldable iPhone model and may include further changes.

No technical details of the vulnerability, exploitation chain, or IOCs were disclosed in this brief advisory. Organizations with users who may be targets of sophisticated, individually-targeted surveillance (journalists, activists, executives, government personnel) should treat this as a priority patch and consider reviewing device integrity where compromise is suspected.

## Mentioned in this report

- Vulnerabilities: CVE-2026-86950

Source reporting: https://isc.sans.edu/diary/rss/33376

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/eb5dac1c-e593-506e-9834-7ea7a171fa9b/apple-patches-actively-exploited-ios-macos-zero-day.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
