securityaffairs.com 30 Sept 2026, 08:04 UTC

CISA Flags Exploited Apple Graphics Flaw Affecting iPhones and Macs

CISA Flags Exploited Apple Graphics Flaw Affecting iPhones and Macs
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Apple CVE-2026-86950, a flaw in CoreGraphics, to its Known Exploited Vulnerabilities (KEV) catalog. Described as an out-of-bounds write that can lead to arbitrary code execution when handling a specially crafted file, the vulnerability was reportedly exploited in an extremely sophisticated targeted attack against specific individuals.

Apple confirms the issue may have affected devices running iOS 26.7 and earlier, iPadOS 26.7 and earlier, and certain macOS versions (Tahoe and Sequoia). The company has released security updates: iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, to address the flaw.

Evidence and impact details remain partial. Apple notes it is aware of reports that the flaw may have been exploited in targeted, high-sophistication attacks, but has not disclosed who was targeted, how many were affected, whether exploitation succeeded, or the exact delivery method for the malicious file. CoreGraphics processes graphics and rendering across Apple’s platforms, meaning the vulnerability could be triggered while the system is interpreting content such as images and PDFs.

The delivery vectors are not confirmed by Apple, but could involve malicious files sent via web pages, email attachments, or messaging apps. Meta Product Security reported the flaw to Apple, adding intrigue given prior Apple-related findings.

CISA’s directive follows Binding Operational Directive 22-01, with agencies required to remediate by 2 October 2026. Private organisations are advised to review the KEV catalog and apply fixes accordingly.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline