CVE-2026-86950

Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) — Exploitation & Unpatched Endpoint Detection

Execution Initial Access Last updated:

Detects exploitation attempts and unpatched-endpoint exposure for CVE-2026-86950, a CWE-787 out-of-bounds write vulnerability affecting the CoreGraphics component across multiple Apple products (iOS, iPadOS, macOS). The flaw is listed in the CISA KEV catalog (BOD 26-04 in scope) and is triggered by processing a maliciously crafted image/PDF, enabling memory corruption and potential arbitrary code execution in the context of the parsing process. Detection strategy combines (1) inventory/telemetry evidence of Apple endpoints running OS builds below the patched versions and (2) behavioral signals of image-parsing crashes, CoreGraphics/ImageIO fault telemetry, and anomalous child-process spawns from renderer/preview processes indicative of exploitation.

Vulnerability Intelligence

KEV — Known Exploited

What is CVE-2026-86950 Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) — Exploitation & Unpatched Endpoint Detection?

Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) — Exploitation & Unpatched Endpoint Detection (CVE-2026-86950) maps to the Execution and Initial Access tactics — the adversary is trying to run malicious code in MITRE ATT&CK.

This page provides production-ready detection logic for Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) — Exploitation & Unpatched Endpoint Detection, covering the data sources and telemetry it touches: Microsoft Defender for Endpoint (DeviceInfo, DeviceProcessEvents). The queries below are rated high severity at medium confidence, and ship for 7 SIEM platforms — KQL, SPL, Elastic, QRadar, Sumo, YARA-L, LogScale.

MITRE ATT&CK

Tactic
Execution Initial Access
Microsoft Sentinel / Defender
kusto
// Unpatched Apple endpoints + CoreGraphics crash correlation for CVE-2026-86950
let PatchedBuilds = dynamic(["23A340","23A341","23B81"]);
DeviceInfo
| where OSPlatform in ("macOS","iOS","iPadOS")
| summarize arg_max(Timestamp, OSVersion, OSBuild=OSVersionInfo, DeviceName) by DeviceId
| extend LikelyUnpatched = iff(isempty(OSBuild) or OSBuild !in (PatchedBuilds), true, false)
| where LikelyUnpatched
| join kind=leftouter (
    DeviceProcessEvents
    | where InitiatingProcessFileName in~ ("Preview","QuickLookUIService","com.apple.quicklook.ThumbnailsAgent","Safari","MobileSafari","imagent")
    | where FileName in~ ("crashpad_handler","ReportCrash","sh","bash","zsh","osascript")
    | project DeviceId, Timestamp, InitiatingProcessFileName, FileName, ProcessCommandLine
) on DeviceId
| project DeviceId, DeviceName, OSVersion, OSBuild, LikelyUnpatched, Timestamp, InitiatingProcessFileName, FileName, ProcessCommandLine

Identifies Apple endpoints reporting OS builds not on the patched list and correlates them with suspicious child processes spawned by image/PDF-rendering processes (Preview, QuickLook, Safari), a signature of CoreGraphics OOB-write exploitation.

high severity medium confidence

Data Sources

Microsoft Defender for Endpoint (DeviceInfo, DeviceProcessEvents)

Required Tables

DeviceInfo DeviceProcessEvents

False Positives

  • Legitimate crash-reporting processes (ReportCrash, crashpad_handler) firing after benign application faults unrelated to exploitation.
  • Endpoints with delayed telemetry reporting stale OSBuild values that lag actual patch state.
  • Developer or QA machines intentionally rendering malformed test images.

Sigma rule & cross-platform mapping

The detection logic for Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) — Exploitation & Unpatched Endpoint Detection (CVE-2026-86950) above is provided in a vendor-neutral form so you can deploy it on any SIEM. The same logic is shipped here as native KQL (Microsoft Sentinel / Defender), SPL (Splunk), Elastic (Elastic Security (EQL)), QRadar (IBM QRadar (AQL)), Sumo (Sumo Logic CSE), YARA-L (Google Chronicle / SecOps), LogScale (CrowdStrike LogScale (CQL)) queries. In Sigma terms, this detection targets the following logsource:

logsource:
  category: process_creation
  product: windows

Browse the community-maintained Sigma rules for this technique:


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Simulate renderer spawning a shell (behavioral proxy)

    Expected signal: ProcessRollup2/DeviceProcessEvents showing osascript spawning sh with parent chain traceable to a scripting/rendering context.

  2. Test 2Generate CoreGraphics-referencing crash artifact

    Expected signal: osquery crashes table entry with responsible_proc Preview and path referencing CoreGraphics.

  3. Test 3Inventory unpatched-build detection

    Expected signal: osquery result event with build not in the patched list.


Response Playbook

Triage

  1. Confirm the affected endpoint's exact OS product and build via MDM/osquery inventory and compare against Apple's patched builds referenced in support.apple.com advisories (149226/149228/149229).
  2. Determine whether the endpoint recently processed untrusted images, PDFs, or messages (Mail/Messages attachments, browsed sites) around the alert time.
  3. Review CoreGraphics/ImageIO crash reports in the macOS crash logs and correlate with any child process spawned by Preview/QuickLook/Safari.
  4. Check the CISA KEV entry and BOD 26-04 applicability to determine remediation deadline for federal in-scope assets.

Containment

  1. Isolate the endpoint from the network via EDR containment if exploitation indicators (shell spawn from renderer, unexpected outbound connections) are present.
  2. Block delivery of the suspected malicious image/PDF at the mail gateway and web proxy, and quarantine the sample.
  3. Enforce accelerated OS patch deployment to the affected Apple build across the fleet via MDM.

Evidence Collection

  1. Preserve macOS crash reports (~/Library/Logs/DiagnosticReports and /Library/Logs/DiagnosticReports) referencing CoreGraphics/ImageIO.
  2. Capture the triggering image/PDF sample, unified logs (log collect), and EDR process/network telemetry for the alert window.

Escalation Criteria

  • ! Escalate to incident response if a renderer process spawned a shell, scripting interpreter, or established outbound C2 connections.
  • ! Escalate to vulnerability management leadership if unpatched in-scope assets exceed the BOD 26-04 remediation deadline.

Investigation Guide

Forensic Artifacts

  • > macOS DiagnosticReports crash logs referencing CoreGraphics/ImageIO
  • > Quarantined malicious image/PDF samples and their download provenance (com.apple.quarantine xattr)
  • > Unified log entries for the rendering process and any spawned child processes

Tuning Guidance

Maintain an accurate list of Apple patched builds from the referenced advisories and update the PatchedBuilds/patched_build lists as new point releases ship. Suppress known-benign crash-reporter processes and developer/QA hosts. Prioritize behavioral (renderer-spawns-shell) alerts over pure inventory alerts to reduce noise, and weight inventory-only findings toward vulnerability management rather than SOC triage.


Hunting Queries

Hunts for image-rendering processes spawning shells and for CoreGraphics/ImageIO crash artifacts across the fleet.

Hunting — KQL
kql
DeviceProcessEvents | where InitiatingProcessFileName in~ ("Preview","QuickLookUIService","Safari","MobileSafari") | where FileName in~ ("sh","bash","zsh","osascript") | project Timestamp, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine
Hunting — SPL
spl
index=osquery sourcetype="osquery:results" name="crashes" (path="*CoreGraphics*" OR path="*ImageIO*") | table host, crash_path, responsible_proc, _time

Atomic Red Team Tests

Test 1 Simulate renderer spawning a shell (behavioral proxy)
macos

Emulates the post-exploitation signal of an image-rendering process launching a shell without exploiting the actual vulnerability.

Command

bash
osascript -e 'do shell script "echo cve-2026-86950-sim > /tmp/cg_oob_sim.txt"'

Cleanup

bash
rm -f /tmp/cg_oob_sim.txt

Expected Telemetry

ProcessRollup2/DeviceProcessEvents showing osascript spawning sh with parent chain traceable to a scripting/rendering context.

Expected Detection

Behavioral rules matching renderer-parent-to-shell child process should fire.

Test 2 Generate CoreGraphics-referencing crash artifact
macos

Writes a synthetic crash report referencing CoreGraphics to validate crash-log ingestion and correlation.

Command

bash
mkdir -p ~/Library/Logs/DiagnosticReports && printf 'Process: Preview\nBinary Images:\n CoreGraphics OOB simulated\n' > ~/Library/Logs/DiagnosticReports/Preview_cve202686950_sim.crash

Cleanup

bash
rm -f ~/Library/Logs/DiagnosticReports/Preview_cve202686950_sim.crash

Expected Telemetry

osquery crashes table entry with responsible_proc Preview and path referencing CoreGraphics.

Expected Detection

SPL/Sumo crash-correlation queries should return the host.

Test 3 Inventory unpatched-build detection
macos

Reports a below-patch OS build via osquery to exercise the unpatched-endpoint inventory detection path.

Command

bash
osqueryi --json "SELECT '23A200' AS build, 'macos' AS os_platform, 'testhost' AS host;"

Cleanup

bash
true

Expected Telemetry

osquery result event with build not in the patched list.

Expected Detection

Inventory-based KQL/SPL queries flag the host as LikelyUnpatched.

Related Detections