Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)
Apple fixed actively exploited Core Graphics zero-day CVE-2026-86950 that enables code execution from a malicious file.
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 to fix CVE-2026-86950, an out-of-bounds write in Core Graphics. Processing a maliciously crafted file can lead to arbitrary code execution. Apple said the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 27. Meta Product Security reported the flaw, and Apple’s iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 updates do not list the CVE.
- CVE-2026-86950 is an out-of-bounds write in Apple Core Graphics.
- A malicious file can trigger arbitrary code execution on vulnerable systems.
- Apple says it may have been exploited against specific targeted individuals.
- Fixes are in iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, and Sequoia 15.8.1.
- Meta Product Security reported the bug; the iOS 27 line is not listed as affected.
Vulnerabilities mentionedAll →
- CVE-2026-869508.8—Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOSpublished · Apple iOS KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86950 | Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOS An out-of-bounds write vulnerability (CWE-787) in Apple's CoreGraphics framework, scored 8.8 (high), allows arbitrary code execution when a device processes a maliciously crafted file, such as a malicious image or document that triggers the vulnerable rendering path. The flaw affects iPhones, iPads, and Macs, and exploitation requires no privileges but does require user interaction — the victim must open or preview the malicious file. Successful exploitation gives the attacker the ability to run code with high impact on confidentiality, integrity, and availability of the affected device. Apple states it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, indicating likely limited but real in-the-wild use. Fixes were shipped in iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1. |
Full article247 words · extracted from helpnetsecurity.com · click to collapse
Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core Graphics framework.
“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27,” the company said, but refrained from providing additional details about the attacks or targets.
About CVE-2026-86950
Core Graphics handles “path-based drawing, transformations, color management, offscreen rendering, patterns, gradients and shadings, image data management, image creation, and image masking, as well as PDF document creation, display, and parsing.”
Reported by Meta Product Security, CVE-2026-86950 is an out-of-bounds write issue that allows for arbitrary code execution when a vulnerable OS processes a maliciously crafted file.
A fix for the flaw is included in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
Apple’s latest operating systems – iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 don’t appear to be affected: those updates were shipped with no published CVE-numbered vulnerabilities.
Nevertheless, all users should upgrade to a fixed version as soon as possible.

In Apple-related news:
Apple’s new iOS 27 feature looks for signs you’re being scammed
Apple parental controls in iOS 27 let kids ask before opening new websites
Apple is building photo verification for the people who need it most

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/29/apple-core-graphics-zero-day-cve-2026-86950-fixed/