CVE-2026-86876

MEDIUM CVSS 3.1: 5.2 EPSS 0.11%
Updated Sep 15, 2026
Apple
Parameter Value
CVSS 5.2 (MEDIUM)
Type CWE-787 (Out-of-bounds Write)
Vendor Apple
Public PoC No

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27, watchOS 27. A sandboxed process may be able to circumvent sandbox restrictions.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

apple:ios and ipados apple:macos apple:watchos apple:visionos