CVE-2026-86950 Sumo Logic CSE · Sumo

Detect Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) — Exploitation & Unpatched Endpoint Detection in Sumo Logic CSE

Detects exploitation attempts and unpatched-endpoint exposure for CVE-2026-86950, a CWE-787 out-of-bounds write vulnerability affecting the CoreGraphics component across multiple Apple products (iOS, iPadOS, macOS). The flaw is listed in the CISA KEV catalog (BOD 26-04 in scope) and is triggered by processing a maliciously crafted image/PDF, enabling memory corruption and potential arbitrary code execution in the context of the parsing process. Detection strategy combines (1) inventory/telemetry evidence of Apple endpoints running OS builds below the patched versions and (2) behavioral signals of image-parsing crashes, CoreGraphics/ImageIO fault telemetry, and anomalous child-process spawns from renderer/preview processes indicative of exploitation.

MITRE ATT&CK

Tactic
Execution Initial Access

Sumo Detection Query

Sumo Logic CSE (Sumo)
sql
_sourceCategory=*apple* OR _sourceCategory=*mdm*
| json field=_raw "os_platform", "os_build", "parent_process", "process_name", "host" nodrop
| where (os_platform matches "*macos*" or os_platform matches "*ios*")
| where !(os_build in ("23A340","23A341","23B81"))
| where parent_process matches /(Preview|QuickLook|Safari|imagent)/
| where process_name matches /(sh|bash|zsh|osascript|ReportCrash|crashpad_handler)/
| count by host, os_build, parent_process, process_name
medium severity low confidence

Surfaces unpatched Apple hosts correlated with image-rendering processes launching shells or crash handlers indicative of CVE-2026-86950 exploitation.

Data Sources

Sumo Logic Apple endpoint collectorMDM inventory ingestion

Required Tables

apple_endpointmdm_inventory

False Positives & Tuning

  • Crash reporters spawned after benign application faults.
  • Hosts lacking os_build in the payload, defaulting to unpatched.
  • Enterprise Safari kiosk workflows launching helper scripts.

Other platforms for CVE-2026-86950


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Simulate renderer spawning a shell (behavioral proxy)

    Expected signal: ProcessRollup2/DeviceProcessEvents showing osascript spawning sh with parent chain traceable to a scripting/rendering context.

  2. Test 2Generate CoreGraphics-referencing crash artifact

    Expected signal: osquery crashes table entry with responsible_proc Preview and path referencing CoreGraphics.

  3. Test 3Inventory unpatched-build detection

    Expected signal: osquery result event with build not in the patched list.


Response Playbook

Triage

  1. Confirm the affected endpoint's exact OS product and build via MDM/osquery inventory and compare against Apple's patched builds referenced in support.apple.com advisories (149226/149228/149229).
  2. Determine whether the endpoint recently processed untrusted images, PDFs, or messages (Mail/Messages attachments, browsed sites) around the alert time.
  3. Review CoreGraphics/ImageIO crash reports in the macOS crash logs and correlate with any child process spawned by Preview/QuickLook/Safari.
  4. Check the CISA KEV entry and BOD 26-04 applicability to determine remediation deadline for federal in-scope assets.

Containment

  1. Isolate the endpoint from the network via EDR containment if exploitation indicators (shell spawn from renderer, unexpected outbound connections) are present.
  2. Block delivery of the suspected malicious image/PDF at the mail gateway and web proxy, and quarantine the sample.
  3. Enforce accelerated OS patch deployment to the affected Apple build across the fleet via MDM.

Evidence Collection

  1. Preserve macOS crash reports (~/Library/Logs/DiagnosticReports and /Library/Logs/DiagnosticReports) referencing CoreGraphics/ImageIO.
  2. Capture the triggering image/PDF sample, unified logs (log collect), and EDR process/network telemetry for the alert window.

Escalation Criteria

  • !Escalate to incident response if a renderer process spawned a shell, scripting interpreter, or established outbound C2 connections.
  • !Escalate to vulnerability management leadership if unpatched in-scope assets exceed the BOD 26-04 remediation deadline.

Investigation Guide

Related Techniques

Forensic Artifacts

  • >macOS DiagnosticReports crash logs referencing CoreGraphics/ImageIO
  • >Quarantined malicious image/PDF samples and their download provenance (com.apple.quarantine xattr)
  • >Unified log entries for the rendering process and any spawned child processes

Tuning Guidance

Maintain an accurate list of Apple patched builds from the referenced advisories and update the PatchedBuilds/patched_build lists as new point releases ship. Suppress known-benign crash-reporter processes and developer/QA hosts. Prioritize behavioral (renderer-spawns-shell) alerts over pure inventory alerts to reduce noise, and weight inventory-only findings toward vulnerability management rather than SOC triage.


Hunting Queries

Hunts for image-rendering processes spawning shells and for CoreGraphics/ImageIO crash artifacts across the fleet.

Hunting — KQL
kql
DeviceProcessEvents | where InitiatingProcessFileName in~ ("Preview","QuickLookUIService","Safari","MobileSafari") | where FileName in~ ("sh","bash","zsh","osascript") | project Timestamp, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine
Hunting — SPL
spl
index=osquery sourcetype="osquery:results" name="crashes" (path="*CoreGraphics*" OR path="*ImageIO*") | table host, crash_path, responsible_proc, _time

Atomic Red Team Tests

Test 1 Simulate renderer spawning a shell (behavioral proxy)
macos

Emulates the post-exploitation signal of an image-rendering process launching a shell without exploiting the actual vulnerability.

Command

bash
osascript -e 'do shell script "echo cve-2026-86950-sim > /tmp/cg_oob_sim.txt"'

Cleanup

bash
rm -f /tmp/cg_oob_sim.txt

Expected Telemetry

ProcessRollup2/DeviceProcessEvents showing osascript spawning sh with parent chain traceable to a scripting/rendering context.

Expected Detection

Behavioral rules matching renderer-parent-to-shell child process should fire.

Test 2 Generate CoreGraphics-referencing crash artifact
macos

Writes a synthetic crash report referencing CoreGraphics to validate crash-log ingestion and correlation.

Command

bash
mkdir -p ~/Library/Logs/DiagnosticReports && printf 'Process: Preview\nBinary Images:\n CoreGraphics OOB simulated\n' > ~/Library/Logs/DiagnosticReports/Preview_cve202686950_sim.crash

Cleanup

bash
rm -f ~/Library/Logs/DiagnosticReports/Preview_cve202686950_sim.crash

Expected Telemetry

osquery crashes table entry with responsible_proc Preview and path referencing CoreGraphics.

Expected Detection

SPL/Sumo crash-correlation queries should return the host.

Test 3 Inventory unpatched-build detection
macos

Reports a below-patch OS build via osquery to exercise the unpatched-endpoint inventory detection path.

Command

bash
osqueryi --json "SELECT '23A200' AS build, 'macos' AS os_platform, 'testhost' AS host;"

Cleanup

bash
true

Expected Telemetry

osquery result event with build not in the patched list.

Expected Detection

Inventory-based KQL/SPL queries flag the host as LikelyUnpatched.

Related Detections