The advisory landed while I was mid-coffee. An out-of-bounds write, CVE-2026-86950, exploited in the wild, and Apple reaching for a phrase it keeps in the top drawer for the bad ones: extremely sophisticated. That language is not marketing. When Apple says it, it means a real campaign burned a real zero-day against real people, and the memory-corruption primitive behind it is the kind that ends in arbitrary code execution. Out-of-bounds writes let an attacker put bytes where bytes should not go — a length check gets skipped, a buffer boundary gets ignored, and now you are scribbling into adjacent memory that decides what the process does next.
So I did the boring thing. I went to patch the fleet. Here is what actually happened.
Hour one: the inventory lied to me
First move was not patching. First move was counting — how many devices, on what versions, and which ones are exposed. I do not trust a remediation I cannot measure before and after.
Apple shipped fixes across the affected platforms simultaneously, which is its usual pattern for an active zero-day: iOS and iPadOS, macOS, and the smaller surfaces that share the same code. I am deliberately not quoting build numbers here because your exact target lives on Apple’s security release page and it moves — pull the fixed version for each platform straight from the advisory and pin your query to that, not to a number I typed from memory.
For the Intune-managed slice, Microsoft Graph gave me the honest count:
The Jamf half I pulled through the Pro API:
The lie: roughly a tenth of the Macs reported an OS version newer than what any human had ever approved. Deferred-update policy plus users hammering “Install Tonight” had quietly moved them. Good for me this week. A governance problem every other week.
The next morning: unmanaged devices don’t show up in any dashboard
The devices that nearly got me were the ones no MDM could see — contractor laptops, a founder’s personal iPad that reads board documents, the exact high-value, lightly-governed targets a sophisticated operator actually wants. For those there is no elegant query. There is a person and a terminal:
On iOS it is Settings > General > Software Update, and you nag until you see a screenshot. Undignified. It works.
What broke, and what I’d say to the next person
Three things broke. A conditional-access rule keyed to an old OS build locked out early patchers for twenty minutes until I updated the minimum-version floor — patch your compliance policy in the same change window as the devices. A pair of Macs stalled on update because the startup volume was full; the fix ships, the install does not. And my “patched” count drifted upward for two days as stragglers synced, so the first report was wrong by design — measure on a rolling basis, not once.
Urgency: this is immediate, not next-cycle, and the calculus is simple. Active exploitation plus Apple’s “extremely sophisticated” framing means someone competent is already spending this bug on a shortlist of targets. If any of your people belong on that shortlist — executives, legal, anyone touching sensitive negotiations — those devices go first, tonight, before you finish counting the rest.
Push the update. Then go find the devices your dashboard forgot, because those are the ones the attacker already remembered.
