securityaffairs.com 29 Sept 2026, 13:28 UTC

Apple Patches CoreGraphics Zero Day Exploited in Targeted iOS Attacks

Apple Patches CoreGraphics Zero Day Exploited in Targeted iOS Attacks
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

APPLE has patched a zero-day in CoreGraphics, tracked as CVE-2026-86950, after it was reportedly exploited in extremely sophisticated targeted attacks against specific iOS users. The flaw is an out-of-bounds write that could allow arbitrary code execution when processing a crafted file. The vulnerability affects iOS 26.7 and earlier, iPadOS 26.7 and earlier, and certain macOS builds (Tahoe and Sequoia).

Apple released security updates to address the issue: iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Apple notes that processing a malicious file may lead to code execution, and that the issue was addressed with improved bounds checking.

The company has not disclosed who was targeted, how many individuals were affected, whether exploitation succeeded, or how attackers delivered the malicious files. CoreGraphics handles graphics and rendering across Apple platforms, so exploitation could occur simply by the system processing a crafted file delivered via a web page, email attachment, or messaging app, though Apple has not confirmed delivery methods for CVE-2026-86950.

Meta’s Product Security team reported the vulnerability to Apple, a link highlighted by Security Affairs as notable given prior Apple-exploitation ties involving Meta’s platforms. The practical response for organisations is clear: identify devices still running affected releases and prioritise applying the relevant updates, especially for executives, researchers, journalists or other high‑value targets. The article also notes that CISA had not yet added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog as of publication.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline