Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple patched CoreGraphics CVE-2026-86950, which may have been exploited in targeted iOS attacks.
Apple released updates for an out-of-bounds write in CoreGraphics, CVE-2026-86950, that can allow arbitrary code execution when processing a malicious file. The company said it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific people on iOS versions before iOS 27. Fixes are in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1; Meta Product Security reported the bug. Apple previously patched a separate dyld issue, CVE-2026-20700, that it said was used in sophisticated attacks.
- CVE-2026-86950 is an out-of-bounds write in CoreGraphics.
- Apple says it may have been used against specific iOS users.
- Patches cover iOS and iPadOS 26.7.1 plus macOS Tahoe and Sequoia.
- Meta Product Security discovered and reported the vulnerability.
- No victim count or first-exploitation date was disclosed.
Vulnerabilities mentionedAll →
- CVE-2026-207007.81%Exploited Memory Corruption Flaw in Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOSpublished · Apple iOS (iPhone OS) KEV
- CVE-2026-869508.8—Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOS
Full article267 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 28, 2026Vulnerability / Endpoint Security
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks.
The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file.
The iPhone maker said the issue was addressed with improved bounds checking. It credited Meta Product Security with discovering and reporting the issue.
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27," it added.
However, the company offered no details on how many individuals were targeted, if any of those attempts were successful, or when the first instance of CVE-2026-86950 exploitation occurred.
The shortcoming has been addressed in the following devices and operating system versions -
- iOS 26.7.1 and iPadOS 26.7.1 - iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
- macOS Tahoe 26.7.1 - Macs running macOS Tahoe
- macOS Sequoia 15.8.1 - Macs running macOS Sequoia
Earlier this February, Apple addressed a memory corruption issue in dyld (CVE-2026-20700, CVSS score: 7.8) that it said had been weaponized in sophisticated cyber attacks.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html