Update your iPhone, iPad, or Mac: Flaw could run attackers’ code
Apple patched CVE-2026-86950, a CoreGraphics flaw possibly exploited in targeted iPhone attacks via malicious files.
Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics that can let an attacker run code when a device processes a maliciously crafted file. Apple says it is aware of a report that the flaw may have been exploited in an extremely sophisticated, highly targeted attack against specific iPhone users on iOS versions before iOS 27. Fixes are in iOS and iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1, addressed with improved bounds checking.