Opens in a new tab

Apple patches CoreGraphics zero-day flaw exploited in targeted attacks

  • Home
  • Blog
  • Apple patches CoreGraphics zero-day flaw exploited in targeted attacks
IPhone displaying a fragmented digital landscape representing the CoreGraphics zero-day exploit

Apple released security updates on Monday to fix a CoreGraphics zero-day vulnerability that was used in targeted attacks against specific individuals on older versions of iOS. Tracked as CVE-2026-86950, the flaw lets a maliciously crafted file trigger arbitrary code execution on affected devices.

What is CVE-2026-86950?

CVE-2026-86950 is an out-of-bounds write weakness inside CoreGraphics, the Apple framework used for two-dimensional vector graphics, image rendering, and text drawing across iOS, iPadOS, macOS, watchOS, and tvOS. Out-of-bounds write bugs allow attackers to write data outside an allocated memory buffer, which can crash a program, corrupt data, or, in the worst case, run attacker-controlled code on the device.

The issue was discovered by Meta Product Security and addressed by Apple with improved bounds checking. Apple warned that the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

Which devices are affected?

The vulnerability reaches a wide range of older and newer hardware:

  • iPhone 11 and later
  • iPad Pro 12.9-inch 3rd generation and later
  • iPad Pro 11-inch 1st generation and later
  • iPad Air 3rd generation and later
  • iPad 8th generation and later
  • iPad mini 5th generation and later
  • Macs running macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1

Which updates fix the flaw?

Apple shipped patched builds for iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Users on the affected hardware should install the corresponding update as soon as it appears in Settings.

How does this fit into Apple’s 2026 patch record?

CVE-2026-86950 is the second zero-day Apple has fixed in active exploitation since the start of the year. The first, CVE-2026-20700, was an arbitrary code execution bug in dyld, the Dynamic Link Editor used by Apple operating systems. Apple patched it in February after reports of exploitation in extremely sophisticated targeted attacks.

Earlier in 2026, Apple also addressed CVE-2025-20701, a high-severity flaw in Beats Studio Buds that let attackers within Bluetooth range spy on users’ conversations. The company also patched older iPhones and iPads against four vulnerabilities targeted in cyberespionage and crypto-theft attacks delivered through the Coruna exploit kit.

In 2025, Apple fixed seven zero-days exploited in the wild:

  • CVE-2025-24085, patched in January
  • CVE-2025-24200, patched in February
  • CVE-2025-24201, patched in March
  • CVE-2025-31200 and CVE-2025-31201, patched in April
  • CVE-2025-43529 and CVE-2025-14174, patched in December

Should everyday users worry?

The exploitation pattern here mirrors the dyld zero-day from earlier in the year: Apple described both as limited to extremely sophisticated attacks against specific targeted individuals. Mass consumer exploitation has not been reported. Even so, the patches are free, small, and already rolling out, so installing them removes any exposure window.

FAQ

What is CVE-2026-86950?

CVE-2026-86950 is an out-of-bounds write vulnerability in Apple’s CoreGraphics framework. Processing a maliciously crafted file can lead to arbitrary code execution on affected iPhone, iPad, and Mac devices.

Which Apple devices are affected by the CoreGraphics zero-day?

The flaw affects iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, iPad mini 5th generation and later, and Macs running macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1.

How many Apple zero-days have been exploited in 2026?

Apple has fixed two zero-days exploited in the wild in 2026: CVE-2026-20700, a dyld arbitrary code execution flaw patched in February, and CVE-2026-86950, the CoreGraphics bug patched in September.


This article summarizes reporting from bleepingcomputer.com.

← All Articles