{"id":415,"date":"2026-10-06T12:44:09","date_gmt":"2026-10-06T12:44:09","guid":{"rendered":"https:\/\/managedt.com\/blog\/apple-core-graphics-zero-day-cve-2026-86950\/"},"modified":"2026-10-09T02:37:13","modified_gmt":"2026-10-09T02:37:13","slug":"apple-core-graphics-zero-day-cve-2026-86950","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/apple-core-graphics-zero-day-cve-2026-86950\/","title":{"rendered":"Apple patches actively exploited zero-day in Core Graphics (CVE-2026-86950)"},"content":{"rendered":"<p>Apple has released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 to close an actively exploited zero-day vulnerability in the Core Graphics framework, tracked as CVE-2026-86950. The flaw, reported by Meta Product Security, allows arbitrary code execution when a device processes a maliciously crafted file, and Apple confirms it was used in highly targeted attacks against specific individuals.<\/p>\n<h2>What is CVE-2026-86950?<\/h2>\n<p>CVE-2026-86950 is an out-of-bounds write vulnerability inside Core Graphics, the Apple framework responsible for path-based drawing, transformations, color management, offscreen rendering, patterns, gradients and shadings, image data management, image creation, image masking, and PDF document creation, display, and parsing. When a device running a vulnerable operating system opens a maliciously crafted file, the flaw can be triggered to write outside the bounds of the intended memory area. That condition can be exploited to execute arbitrary code, letting an attacker run software of their choosing on the affected device.<\/p>\n<h2>Who reported it and how was it exploited?<\/h2>\n<p>The vulnerability was reported by Meta Product Security. Apple&#8217;s advisory acknowledges that the issue was exploited in what it describes as an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. The company did not share additional details about the attacks, the targets, or the threat actor involved. The disclosure pattern, combining an out-of-bounds write in a media-handling framework with a small, named victim set, is consistent with spyware-grade operations that rely on convincing a target to open a single file.<\/p>\n<h2>Which devices and OS versions are affected?<\/h2>\n<p>The fix ships in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Apple&#8217;s newest operating system releases, iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1, were published with no CVE-numbered vulnerabilities listed and do not appear to carry the same exposure. Devices that stay on older branches, including iOS 26 and earlier, iPadOS 26 and earlier, and the prior macOS lines, remain vulnerable until they are moved onto a patched build.<\/p>\n<h2>Why Core Graphics flaws matter<\/h2>\n<p>Core Graphics is the layer the system uses to render images and parse PDF content across iOS, iPadOS, and macOS. A memory corruption bug in that framework is reachable any time a user opens an image or a PDF from Messages, Mail, Safari, or a third-party app that hands file rendering back to the system. Because the trigger is a crafted file rather than a network request, the user does not have to visit a malicious site or install unknown software for the exploit to fire; the file itself is the payload.<\/p>\n<h2>What users should do now<\/h2>\n<p>Install iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, or macOS Sequoia 15.8.1 on every supported device as soon as the update is available. Devices that cannot move to a fixed build should avoid opening image or PDF attachments from unverified sources until a patch can be applied. Enterprises managing fleets should prioritize this update because the vulnerability was already being used in real attacks before a fix was public.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is CVE-2026-86950?<\/h3>\n<p>CVE-2026-86950 is an out-of-bounds write vulnerability in Apple&#8217;s Core Graphics framework that allows arbitrary code execution when a device processes a maliciously crafted file. It was actively exploited in highly targeted attacks.<\/p>\n<h3>Which Apple updates fix CVE-2026-86950?<\/h3>\n<p>The fix is included in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.<\/p>\n<h3>Is iOS 27 affected by CVE-2026-86950?<\/h3>\n<p>No. iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 were released with no CVE-numbered vulnerabilities and do not appear to be affected by the flaw.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is CVE-2026-86950?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"CVE-2026-86950 is an out-of-bounds write vulnerability in Apple's Core Graphics framework that allows arbitrary code execution when a device processes a maliciously crafted file. It was actively exploited in highly targeted attacks.\"}},{\"@type\":\"Question\",\"name\":\"Which Apple updates fix CVE-2026-86950?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The fix is included in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.\"}},{\"@type\":\"Question\",\"name\":\"Is iOS 27 affected by CVE-2026-86950?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 were released with no CVE-numbered vulnerabilities and do not appear to be affected by the flaw.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/29\/apple-core-graphics-zero-day-cve-2026-86950-fixed\/\" target=\"_blank\" rel=\"nofollow noopener\">helpnetsecurity.com<\/a>.<\/p>\n<p><!-- seo-pro:slop-fixed --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple ships iOS 26.7.1, iPadOS 26.7.1, and macOS fixes for an out-of-bounds write flaw in Core Graphics that was exploited in targeted attacks.<\/p>\n","protected":false},"author":3,"featured_media":414,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-415","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/415","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=415"}],"version-history":[{"count":2,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/415\/revisions"}],"predecessor-version":[{"id":486,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/415\/revisions\/486"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/414"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=415"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=415"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=415"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}