Apple CoreGraphics zero-day CVE-2026-86950 patched

Apple has released emergency security updates for iOS, iPadOS and macOS to address an actively exploited CoreGraphics zero-day vulnerability tracked as CVE-2026-86950, warning that the flaw has already been used in “extremely sophisticated” attacks against specific targeted individuals.[2][6][1][7]

The bug is described in Apple’s advisories as an out-of-bounds write issue in the CoreGraphics framework that can be triggered when a device processes a maliciously crafted file, allowing arbitrary code execution on vulnerable systems.[2][6][1][5] Security vendors tracking the flaw, including OpenCVE and ThreatClaw, assign it a CVSS v3.1 base score of 8.8, rating it high severity due to the potential for complete compromise of affected devices.[13][11][9]

Apple notes that it is aware of reports that CVE-2026-86950 “may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27,” but has not shared details on the threat actors, targeting, or infection chain.[2][6][14][4] Because CoreGraphics underpins 2D graphics and PDF rendering across the operating system, researchers at SecurityWeek warn that malicious files could plausibly be delivered via web content, email attachments or messaging apps, potentially enabling zero-click or low-interaction exploitation on exposed devices.[7][10]

The zero-day affects both mobile and desktop platforms, with fixes shipping in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, where Apple says it mitigated the issue by improving bounds checking in CoreGraphics.[2][6][1][5] Apple’s security release notes list impacted mobile hardware as iPhone 11 and later, iPad Pro 12.9‑inch (third generation and later), iPad Pro 11‑inch (first generation and later), iPad Air (third generation and later), iPad (eighth generation and later), and iPad mini (fifth generation and later).[12][4][8] Newer platforms such as iOS 27.0.1, iPadOS 27.0.1 and macOS Golden Gate 27.0.1 are not currently documented as affected, and their latest releases shipped without any CVE entries.[1][14]

The vulnerability was reported to Apple by Meta Product Security, but neither Meta nor Apple has published deeper technical details on how it was discovered or the exploit techniques observed in the wild.[2][1][7][4] Security outlets including Help Net Security, The Register and The Hacker News note that CVE-2026-86950 continues a pattern of Apple patching multiple zero-day flaws under active exploitation in 2026, underscoring the sustained interest of advanced threat actors in Apple’s platforms.[1][4][10]

So far, there is no public proof-of-concept exploit code or formal attribution linking the zero-day to a known spyware vendor or state-backed group, but the highly targeted nature of the attacks has prompted speculation that it may be part of a sophisticated surveillance campaign.[7][10][1] With exploitation already observed, defenders are advised to prioritize deployment of iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, monitor for unusual file-processing activity, and treat older, unpatched iOS builds as at heightened risk until they receive the latest updates.[2][6][12][8]

References

  1. Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950) – Help Net Security
  2. About the security content of iOS 26.7.1 and iPadOS 26.7.1
  3. Apple patches CoreGraphics zero-day already exploited in targeted attacks
  4. Apple zero-day patch fixes flaw exploited in targeted attacks
  5. About the security content of macOS Tahoe 26.7.1 – Apple Support
  6. www.securityweek.com · apple-patches-meta-reportedApple Patches Zero-Day Linked to ‘Extremely Sophisticated …
  7. Apple patches iOS vulnerability, are crypto wallets still at risk?
  8. CVE-2026-86950 – Exploits & Severity – Feedly
  9. Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
  10. www.threatclaw.ai › cve › CVE-2026-86950CVE-2026-86950 — HIGH Vulnerability | CVSS 8.8 | ThreatClaw
  11. Apple security releases
  12. CVE-2026-86950 – Vulnerability Details – OpenCVE
  13. iOS 26.7.1 Fixes Vulnerability Used in Targeted Attacks

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply