{"id":391,"date":"2026-10-06T11:23:11","date_gmt":"2026-10-06T11:23:11","guid":{"rendered":"https:\/\/managedt.com\/blog\/apple-coregraphics-zero-day-meta-ios-macos-patch\/"},"modified":"2026-10-06T11:23:12","modified_gmt":"2026-10-06T11:23:12","slug":"apple-coregraphics-zero-day-meta-ios-macos-patch","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/apple-coregraphics-zero-day-meta-ios-macos-patch\/","title":{"rendered":"Apple Patches CoreGraphics Zero-Day Reported by Meta, Possibly Exploited in Targeted Attacks"},"content":{"rendered":"<p>Apple has released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 to patch a CoreGraphics zero-day vulnerability, tracked as CVE-2026-86950, that the company says may have been exploited in highly targeted attacks against specific individuals. Apple credited Meta&#8217;s product security team for reporting the flaw, and the latest iOS 27 and macOS Golden Gate 27 releases do not appear to be affected.<\/p>\n<h2>What is CVE-2026-86950?<\/h2>\n<p>CVE-2026-86950 is an out-of-bounds write vulnerability in the CoreGraphics component that handles 2D graphics and PDF rendering across Apple&#8217;s operating systems. Processing a specially crafted file can trigger arbitrary code execution, which means a malicious file could run attacker-controlled code on the device.<\/p>\n<p>Because CoreGraphics underpins rendering across the OS, a malicious file could arrive through several channels, including web pages, email attachments, or messaging apps. Automatic attachment and link previews in those apps could enable zero-click exploitation, where the target does not need to interact with the file for the attack to succeed.<\/p>\n<p>Apple&#8217;s advisory states that the company is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. While both iOS and macOS are impacted, the advisory suggests that attacks have only been observed against iOS.<\/p>\n<h2>Who reported the flaw and how is it connected to previous attacks?<\/h2>\n<p>Apple learned of the vulnerability from Meta&#8217;s product security team. In response to an inquiry, Meta said that, as part of its routine security work, it regularly reports vulnerabilities found in third-party software to other vendors so they can be patched. Meta did not provide information on the attacks exploiting CVE-2026-86950 or say whether WhatsApp was involved.<\/p>\n<p>The Meta involvement is notable in light of a similar incident from the previous year, when WhatsApp said a vulnerability in its iOS and macOS apps (CVE-2025-55177) was likely used alongside the Apple ImageIO zero-day CVE-2025-43300 in zero-click attacks aimed at fewer than 200 users. It is unclear whether the newly patched CoreGraphics flaw was exploited through WhatsApp.<\/p>\n<h2>What versions are affected and what should users do?<\/h2>\n<p>The flaw has been patched in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. The latest iOS 27 and macOS Golden Gate 27 do not appear to be affected.<\/p>\n<p>Users on iOS 26 and earlier releases, and on the affected macOS versions, should install the updates as soon as possible, especially those who may be at higher risk of targeted intrusion.<\/p>\n<p>CISA has not yet added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog. If added, this would be the ninth Apple product flaw listed in the catalog this year.<\/p>\n<h2>How does this CoreGraphics issue compare to past Apple zero-days?<\/h2>\n<p>The pattern of a CoreGraphics-class flaw being reported by an outside security team and linked to highly targeted exploitation echoes earlier incidents. The prior year pairing of an Apple ImageIO zero-day (CVE-2025-43300) with a WhatsApp app flaw (CVE-2025-55177) showed that attackers can chain vulnerabilities across vendor boundaries to deliver zero-click payloads. CVE-2026-86950 fits that same family of risk: a widely used rendering component, a file as the trigger vector, and exploitation that Apple describes as extremely sophisticated against specific individuals.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is CVE-2026-86950?<\/h3>\n<p>It is an out-of-bounds write vulnerability in the CoreGraphics component of iOS and macOS that can lead to arbitrary code execution when a specially crafted file is processed. Apple has patched it in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.<\/p>\n<h3>Was CVE-2026-86950 exploited in the wild?<\/h3>\n<p>Apple&#8217;s advisory says the company is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. No further details on the attacks have been shared, and CISA has not yet added the flaw to its Known Exploited Vulnerabilities catalog.<\/p>\n<h3>Who reported the CoreGraphics zero-day to Apple?<\/h3>\n<p>Meta&#8217;s product security team reported the vulnerability to Apple. Meta said it regularly reports vulnerabilities found in third-party software to other vendors as part of routine security work, and did not confirm or deny whether WhatsApp was involved in any exploitation.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is CVE-2026-86950?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"It is an out-of-bounds write vulnerability in the CoreGraphics component of iOS and macOS that can lead to arbitrary code execution when a specially crafted file is processed. Apple has patched it in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.\"}},{\"@type\":\"Question\",\"name\":\"Was CVE-2026-86950 exploited in the wild?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Apple's advisory says the company is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. No further details on the attacks have been shared, and CISA has not yet added the flaw to its Known Exploited Vulnerabilities catalog.\"}},{\"@type\":\"Question\",\"name\":\"Who reported the CoreGraphics zero-day to Apple?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Meta's product security team reported the vulnerability to Apple. Meta said it regularly reports vulnerabilities found in third-party software to other vendors as part of routine security work, and did not confirm or deny whether WhatsApp was involved in any exploitation.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.securityweek.com\/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack\/\" target=\"_blank\" rel=\"nofollow noopener\">securityweek.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple rolls out iOS 26.7.1, iPadOS 26.7.1, and macOS updates to fix a CoreGraphics out-of-bounds write flaw that may have been used in targeted attacks.<\/p>\n","protected":false},"author":3,"featured_media":390,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-391","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/391","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=391"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/391\/revisions"}],"predecessor-version":[{"id":392,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/391\/revisions\/392"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/390"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=391"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=391"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=391"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}