securityaffairs.com 1 Oct 2026, 12:08 UTC

Apple Patches CoreGraphics Zero Day Exploited in Targeted Attacks

Apple Patches CoreGraphics Zero Day Exploited in Targeted Attacks
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Status Unknown

APPLE has patched a zero‑day in CoreGraphics tracked as CVE-2026-86950, after researchers reported that it could be triggered by processing specially crafted files to cause arbitrary code execution. The flaw is described as an out‑of‑bounds write in the font rendering path, related to how CoreGraphics converts coordinates and builds a bounding box for rendering.

Apple notes that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on earlier iOS versions, though details on who was targeted, how many were affected, whether exploitation succeeded, or how the malicious files were delivered remain undisclosed.

The vulnerability affects iOS 26.7 and earlier, iPadOS 26.7 and earlier, and supported macOS Tahoe and macOS Sequoia versions, with patches introduced in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. CoreGraphics handles graphics and rendering across Apple platforms, meaning any file rendered to a thumbnail or preview could potentially trigger the flaw without user interaction beyond receiving the file.

A public PoC was released by Calif, based on a detailed analysis titled The Great Glyph Grift, showing a crash rather than a working exploit; researchers emphasise that turning the crash into code execution would require additional work. The advisory confirms the possibility of exploitation but provides limited operational detail, and the security community awaits fuller attribution and impact assessments.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline