APPLE has released updated iOS and macOS versions to address a zero-day vulnerability that attackers are actively weaponising in targeted attacks. The flaw, CVE-2026-86950, is an out-of-bounds write in Apple's CoreGraphics framework that processes graphics data, with a CVSS score of 8.8. Apple says the exploitation is occurring in highly targeted campaigns against specific individuals on versions of iOS prior to iOS 27, and that mitigations involve code changes to prevent writing beyond allocated memory.
The vulnerability affects a broad range of Apple devices, including iPhones back to the iPhone 11 and multiple generations of iPads. The US CISA has added CVE-2026-86950 to its Known Exploited Vulnerabilities catalogue, directing federal agencies to apply Apple’s mitigations and to conduct forensic triage by 2 October to determine whether compromise has occurred.
Industry commentary emphasises that the attacks appear to be highly sophisticated and narrow in target scope, suggesting a potential nation-state or spyware firm involvement. Analysts note the graphics stack component used across Apple OSes is a recurring pivot point for exploits, and urge organisations with Apple devices in enterprise environments to accelerate patching, enforce minimum OS versions, and ensure devices are managed and compliant to reduce latency and exposure.