Apple Fixes iOS Zero-Day Exploited in Sophisticated Targeted Attacks
Apple patched actively exploited CoreGraphics zero-day CVE-2026-86950 in iOS/iPadOS 26.7.1, enabling arbitrary code execution via crafted files in targeted attacks.
Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026 to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics that allows arbitrary code execution when a device processes a maliciously crafted file. Apple acknowledged reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 27. Meta Product Security reported the vulnerability, and the fix implements improved bounds checking. Updates cover iPhone 11 and later plus most recent iPads.
- Zero-day CVE-2026-86950: out-of-bounds write in CoreGraphics enables arbitrary code execution
- Apple says flaw may have been exploited in sophisticated attacks on targeted individuals
- Patches shipped in iOS 26.7.1 / iPadOS 26.7.1 for iPhone 11 and later
- Delivery method, exploit samples, and victim details undisclosed; prioritize patching high-risk personnel
Vulnerabilities mentionedAll →
- CVE-2026-869508.8—Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOSpublished · Apple iOS KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86950 | Out-of-Bounds Write in Apple CoreGraphics Enables Code Execution on iOS and macOS An out-of-bounds write vulnerability (CWE-787) in Apple's CoreGraphics framework, scored 8.8 (high), allows arbitrary code execution when a device processes a maliciously crafted file, such as a malicious image or document that triggers the vulnerable rendering path. The flaw affects iPhones, iPads, and Macs, and exploitation requires no privileges but does require user interaction — the victim must open or preview the malicious file. Successful exploitation gives the attacker the ability to run code with high impact on confidentiality, integrity, and availability of the affected device. Apple states it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, indicating likely limited but real in-the-wild use. Fixes were shipped in iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1. |
Full article472 words · extracted from gbhackers.com · click to collapse
Apple has released iOS 26.7.1 and iPadOS 26.7.1 to address CVE-2026-86950, a zero-day vulnerability in CoreGraphics that may have been exploited in sophisticated, targeted attacks against specific individuals.
Apple’s latest security updates fix an out-of-bounds write vulnerability in CoreGraphics, the graphics rendering framework used on iPhone and iPad devices. This flaw, tracked as CVE-2026-86950, could allow arbitrary code execution if a target processes a maliciously crafted file.
Apple Patches Active Zero-Day
Apple has confirmed it is aware of reports suggesting that this vulnerability “may have been exploited in an extremely sophisticated attack against specific targeted individuals” on iOS versions before iOS 27.
However, the company did not disclose any exploit samples, the infrastructure used in the attacks, the specific malicious file format, or details about the affected individuals.
Meta Product Security initially reported the vulnerability. Apple addressed the issue by implementing better bounds checking, which prevents data from being written outside of its allocated memory space.
Out-of-bounds write vulnerabilities can cause memory corruption when an application writes attacker-controlled data beyond the limits of an allocated buffer. If successfully exploited, these flaws can enable arbitrary code execution within the vulnerable process.
Because CoreGraphics handles visual and document-related content across Apple’s ecosystem, an attacker could use a specially crafted file to trigger the vulnerability when a vulnerable device opens, previews, or otherwise processes it.
Apple has not confirmed the attack delivery method, so it is unclear whether the attacks involved images, documents, messaging attachments, web content, or another file-processing method.
The description of the exploitation as “extremely sophisticated” indicates that the vulnerability may have been used in a targeted intrusion operation rather than widespread opportunistic attacks.
Such campaigns typically target high-value individuals, including journalists, government officials, executives, activists, diplomats, and users with access to sensitive organizational data.
Apple released iOS 26.7.1 and iPadOS 26.7.1 on September 28, 2026. The updates are available for the iPhone 11 and later, iPad Pro 12.9-inch models (third generation and later), iPad Pro 11-inch models (first generation and later), iPad Air (third generation and later), iPad (eighth generation and later), and iPad mini (fifth generation and later).
Users should install the updates through **Settings > General > Software Update**. Enterprise security teams should prioritize deployment through mobile device management platforms, especially for executives, administrators, journalists, and other high-risk personnel.
Organizations should also verify patch compliance, identify devices that can’t update, and monitor for unusual application crashes or suspicious file delivery activity. Until all eligible devices are updated, users should treat unexpected attachments and files received through email, messaging applications, or collaboration platforms with caution.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.