Apple patches CoreGraphics flaw CVE-2026-86950 after targeted reports
Apple’s Sept. 28 updates fix CoreGraphics CVE-2026-86950, which it says may have been used in sophisticated attacks on specific pre-iOS 27 users.
On September 28, 2026, Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics—the graphics engine that draws the interface, per TechCrunch—that can allow arbitrary code execution when a device processes a maliciously crafted file; the fix is improved bounds checking, and Meta Product Security reported the bug. Apple said it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 27. Sources disagree on certainty: SANS says the flaw is already being exploited, and Cyber Security News, GBHackers, Help Net Security, and The Register describe it as actively or already exploited in headlines or leads, while The Hacker News, Malwarebytes, TechCrunch, and Qualys’s main account retain Apple’s hedged wording (a Qualys bullet says it was used). It affects iOS and iPadOS 26.7 and earlier and supported macOS Tahoe and Sequoia, including iPhone 11 and later, iPad Pro, iPad Air, iPad (8th generation and later), and iPad mini (5th generation and later); iOS 27, iPadOS 27, and macOS 27 are not affected—SANS says the 27-branch update is functional only, and Help Net Security notes iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 do not list the CVE—though TechCrunch says about four in five iPhones still run iOS 26 and that a successful exploit could expose a broad range of personal data. Delivery method, exploit samples, victim count, and threat actors were not disclosed; Security Affairs said CISA had not yet added the CVE to its KEV catalog, and Qualys QIDs 388845, 388846, and 610810 detect vulnerable assets. The Register counts this as Apple’s seventh zero-day fix of 2026; TechCrunch separately notes zero-click CVE-2026-86869, fixed in the 27 releases, triggerable by a malicious iMessage and able to bypass BlastDoor, with use before the fix unconfirmed and credit to ironPeak and Meta, while earlier reports also cite prior exploited bugs CVE-2026-20700 (a dyld issue), CVE-2025-43300, and CVE-2025-55177.
- CVE-2026-86950 is an out-of-bounds write in CoreGraphics that can allow arbitrary code execution when a device processes a maliciously crafted file; Apple fixed it with improved bounds checking.
- Updates released September 28, 2026: iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Meta Product Security reported the bug.
- Apple says it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS before iOS 27. SANS says it is already being exploited; several headlines call it…
Coverage timelineoldest first · each row is one article
- · 1d agoApple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
The Hacker News· 83
Apple patched CoreGraphics CVE-2026-86950, which may have been exploited in targeted iOS attacks.
- · 22h agoApple Emergency Patch for iOS 26/macOS26/macOS15 (CVE-2026-86950), (Mon, Sep 28th)
SANS Internet Storm Center· 84
Apple patched exploited CVE-2026-86950 in iOS 26, macOS 26, and macOS 15 after targeted attacks.
- · 14h agoAPPLE-SA-09-28-2026-1 iOS 26.7.1 and iPadOS 26.7.1
Full Disclosure· 48
Apple patched a CoreGraphics flaw in iOS 26.7.1 and iPadOS 26.7.1 that may allow code execution via a crafted file.
Vulnerabilities in this storyAll →
- CVE-2025-4330010.032%Actively Exploited Out-of-Bounds Write in Apple iOS/iPadOS/macOS Image I/Opublished · Apple iOS KEV PoC