Critical Apple Zero-Day Vulnerability Actively Exploited in Attacks
Apple patched actively exploited CoreGraphics zero-day CVE-2026-86950 enabling arbitrary code execution via crafted files in targeted attacks on iOS users.
Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026, fixing CVE-2026-86950, an out-of-bounds write in CoreGraphics that allows arbitrary code execution when a device processes a maliciously crafted file. Apple states the flaw may have been exploited in an extremely sophisticated attack against specifically targeted individuals on iOS versions before iOS 27, a pattern consistent with spyware operations. The vulnerability affects iPhone 11 and later plus supported iPad Pro, iPad Air, iPad, and iPad mini models, and was reported by Meta Product Security.
- Out-of-bounds write in CoreGraphics enables arbitrary code execution via crafted files
- Apple says flaw may have been exploited against targeted individuals on pre-iOS 27
- Fixes shipped in iOS 26.7.1 and iPadOS 26.7.1 on September 28
- Affects iPhone 11 and later and supported iPads; reported by Meta
Vulnerabilities mentionedAll →
- CVE-2026-869508.8—Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOSpublished · Apple iOS KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86950 | Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOS An out-of-bounds write vulnerability (CWE-787) in Apple's CoreGraphics framework, scored 8.8 (high), allows arbitrary code execution when a device processes a maliciously crafted file, such as a malicious image or document that triggers the vulnerable rendering path. The flaw affects iPhones, iPads, and Macs, and exploitation requires no privileges but does require user interaction — the victim must open or preview the malicious file. Successful exploitation gives the attacker the ability to run code with high impact on confidentiality, integrity, and availability of the affected device. Apple states it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, indicating likely limited but real in-the-wild use. Fixes were shipped in iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1. |
Full article519 words · extracted from cybersecuritynews.com · click to collapse
Apple has released iOS 26.7.1 and iPadOS 26.7.1 to fix a critical zero-day vulnerability that it says may have been exploited in an extremely sophisticated attack against specifically targeted individuals.
The security issue, tracked as CVE-2026-86950, affects the CoreGraphics framework, a fundamental Apple component responsible for rendering graphics, images, and documents across iPhones and iPads.
Successful exploitation could allow attackers to execute arbitrary code on a vulnerable device by convincing a victim to process a maliciously crafted file.
Apple released the updates on September 28, 2026, and urged users to install them as soon as possible. The vulnerability affects iPhone 11 and later models, along with several supported iPad Pro, iPad Air, iPad, and iPad mini devices.
Apple Zero-Day Vulnerability Exploited
Apple confirmed CVE-2026-86950 may have been exploited against specific individuals running iOS versions before iOS 27, suggesting a highly targeted attack rather than a widespread campaign.
Such attacks are commonly associated with spyware operations, intelligence collection, surveillance activity, or attacks against high-value users such as journalists, activists, executives, government personnel, and security researchers.
Apple did not disclose technical details about the attackers, the targeted victims, the malicious files used in the attack, or whether the vulnerability was chained with other zero-day flaws. The company typically limits disclosure while users deploy security updates and while ongoing investigations continue.
The vulnerability exists in CoreGraphics and stems from an out-of-bounds write. This class of memory-safety flaw occurs when software writes data outside the allocated memory boundary.
An attacker may be able to craft a specially designed file that triggers the vulnerable code path when the device opens, previews, downloads, or otherwise processes it. If exploitation succeeds, the attacker could gain arbitrary code execution privileges within the affected process.
Arbitrary code execution is a serious security impact because it may allow attackers to run unauthorized commands, install malicious components, access sensitive information, or establish a foothold for further compromise. The final impact depends on the application processing the file and any additional vulnerabilities available to an attacker.
Apple addressed the issue by implementing improved bounds checking, which helps prevent the affected software component from writing data outside valid memory locations.
The update is available for iPhone 11 and newer iPhone models. Affected iPad systems include iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later), and iPad mini (5th generation and later).
Users should update their devices through Settings > General> Software Update. Organizations managing Apple fleets should verify patch deployment through their mobile device management platforms and identify devices that remain on older iOS or iPadOS releases.
CVE-2026-86950 was reported by Meta Product Security. Apple’s acknowledgment highlights the ongoing risk posed by zero-day vulnerabilities in file-processing components, particularly when used in targeted attacks against selected targets.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.