Apple has shipped emergency updates for iOS, iPadOS and macOS to fix CVE-2026-86950, a CoreGraphics zero-day that the company says was used in an “extremely sophisticated” attack against specific targeted individuals.[2][6][11] The flaw has been addressed in iOS 26.7.1 and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, with security notes and third‑party coverage tying the fixes to releases on September 28, 2026.[1][3][14]
CVE-2026-86950 is described as an out-of-bounds write issue in the CoreGraphics component that can be triggered when a device processes a maliciously crafted file.[1][2][7] Successful exploitation allows arbitrary code execution, giving an attacker the ability to run their own code on affected devices, and multiple advisories classify the bug as high severity because it can be exploited remotely through content delivered over messaging, email or the web.[4][5][12] The vulnerability was reported to Apple by Meta Product Security, underscoring ongoing cross‑vendor collaboration around mobile spyware and surveillance threats.[6][13]
Apple’s advisory notes that the company is aware of a report that CVE-2026-86950 “may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27,” language echoed in several security write‑ups that treat the flaw as an actively exploited zero‑day.[2][9][11] Public reporting so far has not attributed the activity to a named threat group or nation‑state, but the characterization suggests a well‑resourced actor and a likely focus on high‑value or politically sensitive targets rather than broad consumer exploitation.[6][12][14] Researchers also point out that Apple’s latest platform releases—iOS 27.0.1, iPadOS 27.0.1 and macOS Golden Gate 27.0.1—do not list any CVE entries, indicating that the zero‑day was found and fixed on older branches while the new versions shipped clean.[6][13]
According to regional CERT and government advisories, the vulnerability affects iOS and iPadOS versions prior to 26.7.1 and macOS Tahoe prior to 26.7.1, as well as macOS Sequoia prior to 15.8.1.[4][5][12] Device‑level guidance highlights risk for iPhone 11 and later and a wide range of recent iPad models, including iPad Pro 12.9‑inch (3rd generation and later), iPad Pro 11‑inch (1st generation and later), iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.[11][12][13] Organizations running mixed Apple fleets should assume that any handset or laptop not yet on the specified patch levels remains exposed.
National cybersecurity agencies warn that a remote attacker could exploit CVE-2026-86950 simply by delivering a maliciously crafted file, using it as a foothold for code execution and potentially chaining it with other bugs to gain full device compromise.[4][5][12] Enterprise defenders are urged to fast‑track deployment of iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 across managed fleets, prioritize high‑risk users such as executives and journalists, and tighten monitoring around file‑handling workflows where CoreGraphics is invoked.[1][3][11] With few technical details publicly disclosed, patching remains the most reliable defense, and security teams should treat this zero‑day as a likely component in targeted spyware campaigns rather than a routine bug fix.[6][12][13]
References
- NVD-CVE-2026-86950 – NIST
- Untitled
- About the security content of macOS Tahoe 26.7.1 – Apple Support
- Apple Products Remote Code Execution Vulnerability
- High-Severity Vulnerability in Apple Products
- Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950) – Help Net Security
- Apple Patches Zero-Day Linked to ‘Extremely …
- CVE-2026-86950
- Apple Patches CoreGraphics Zero Day Exploited in Attacks
- Apple Warns Users iOS Vulnerability Exploited in Attack (CVE-2026-86950)
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted …
- Apple Patches iPhone Zero-Day Exploited in Attacks; Rival Meta Caught It
