www.infosecurity-magazine.com 30 Sept 2026, 08:45 UTC

Apple Patches CoreGraphics Zero Day Exploited in Targeted iPhone Attacks

CyberSIXT Evidence Panel

APPLE has released a security update for a zero-day in CoreGraphics that it says may have been exploited in an extremely sophisticated attack. The flaw is tracked as CVE-2026-86950, with Apple noting that processing a maliciously crafted file could lead to arbitrary code execution. The company says it is aware of reports that the issue was exploited in targeted attacks against specific individuals on iOS versions prior to iOS 27.

The vulnerability affects the CoreGraphics rendering framework on iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. Mac users are also affected on macOS Sequoia 15.8.1 and Tahoe 26.7.1, with Apple confirming fixes in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.

Industry commentary emphasises governance considerations for executives who commonly receive policy exemptions, urging organisations to reassess update enforcement, high-risk personnel protections, and incident response readiness should a device be compromised. The report situates CVE-2026-86950 alongside previously disclosed issues such as CVE-2025-24200 and CVE-2026-86869, underscoring the ongoing risks from high-value targets and the need for timely patches.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline