Junglewise Threat Intelligence

CVE-2026-86869: Apple Accelerate Framework out-of-bounds write in image processing

CVE-2026-86869 · Severity: medium · CVSS 6.5 · Published 2026-09-14

Technologies: Apple macOS, Apple Iphone Os, Apple iPadOS. Vendors: Apple.

Executive brief

Apple's Accelerate Framework, a core library used for image and media processing across iPhones, iPads, and Macs, contains an out-of-bounds memory write vulnerability. Processing a maliciously crafted image can crash the affected application, disrupting normal user operations. While the immediate impact is limited to app termination, out-of-bounds writes can be leveraged for more severe attacks in certain contexts.

Technical details

CVE-2026-86869 is an out-of-bounds write vulnerability in the Accelerate Framework's image processing logic. The vulnerability exists due to insufficient bounds checking when handling image data. An attacker can craft a malicious image file that, when processed by any application using the Accelerate Framework, triggers a memory write beyond allocated buffer boundaries. The attack requires no special privileges or network access—only that a user or app process the malicious image. The vulnerability is fixed through improved bounds checking in iOS 26.7, iPadOS 26.7, and macOS Golden Gate 27, released September 14, 2026.

Affected products

  • Apple iOS before 26.7
  • Apple iPadOS before 26.7
  • Apple macOS before Golden Gate 27

Timeline

  • 2026-09-14: disclosed: Security advisory published alongside iOS 26.7, iPadOS 26.7, and macOS Golden Gate 27 release
  • 2026-09-14: patched: Fixed in iOS 26.7, iPadOS 26.7, and macOS Golden Gate 27

References

Related threats