Search
Find merged stories by title or summary.
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, tracked as CVE-2026-86950 , in CoreGraphics that attackers may have exploited to target specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when the system processes a specially crafted file. The vulnerability affects iOS 26. 7 and earlier versions before iOS 27, as well as iPadOS 26. 7 and earlier and supported versions of macOS Tahoe and macOS Sequoia. Apple released iOS 26. 7. 1, iPadOS 26. 7. 1, macOS Tahoe 26. 7. 1 and macOS Sequoia 15. 8. 1 to address the issue. “Processing a maliciously crafted file may lead to arbitrary code execution.
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working
Apple Patches CoreGraphics Zero Day Exploited in Attacks
Apple has patched CVE-2026-86950, a zero-day bug in the iOS CoreGraphics engine
U.S. CISA adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8. 8), to its Known Exploited Vulnerabilities (KEV) catalog . This week, Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability CVE-2026-86950 in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when the system processes a specially crafted file. The vulnerability affects iOS 26. 7 and earlier versions before iOS 27, as well as iPadOS 26. 7 and earlier and supported versions of macOS Tahoe and macOS Sequoia. Apple released iOS 26. 7. 1, iPadOS 26. 7.
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks
Apple patched zero-day CVE-2026-86950 in CoreGraphics, exploited in sophisticated targeted attacks against specific iOS users. Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when the system processes a specially crafted file. The vulnerability affects iOS 26. 7 and earlier versions before iOS 27, as well as iPadOS 26. 7 and earlier and supported versions of macOS Tahoe and macOS Sequoia. Apple released iOS 26. 7. 1, iPadOS 26. 7. 1, macOS Tahoe 26. 7. 1 and macOS Sequoia 15. 8. 1 to address the issue. “Processing a maliciously crafted file may lead to arbitrary code execution.
Apple patches CoreGraphics flaw linked to targeted iPhone attacks
Apple has released security updates for iPhones, iPads, and Macs to fix a CoreGraphics vulnerability that may have been exploited in a highly targeted attack. The flaw, tracked as CVE-2026-86950, could allow arbitrary code execution when a device processes a maliciously crafted file. In its security advisory, Apple said it was aware of a report … The post Apple patches CoreGraphics flaw linked to targeted iPhone attacks appeared first on CyberInsider .
Apple Patches iPhone CoreGraphics Flaw Allowing Arbitrary Code Execution
Apple has released iOS 26. 7. 1 and iPadOS 26. 7. 1 to address CVE-2026-86950, a CoreGraphics memory-corruption vulnerability that could allow arbitrary code execution when a device processes a maliciously crafted file. The flaw may have been exploited in an “extremely sophisticated attack” targeting specific individuals on iOS versions released before iOS 27. Released on September 28, 2026, the security update fixes an out-of-bounds write in CoreGraphics, Apple’s graphics-rendering framework used throughout iOS and iPadOS to process visual and document-related content. Apple Patches iPhone CoreGraphics Flaw Tracked as CVE-2026-86950, the bug exists in how CoreGraphics handles certain attacker-controlled file data. An out-of-bounds write occurs when software writes data outside its allocated memory region.
NVD-CVE-2026-86950 - National Institute of Standards and Technology (.gov)
NVD-CVE-2026-86950 National Institute of Standards and Technology (.gov)
[CISA] CVE-2026-86950 - Confirmed Exploitation
CVE-2026-86950 CISA Catalog: Confirmed Status: Yes Exploited: 2026-09-29 00:00 UTC Status Updated: 1 Evidence Sources: 2026-09-29 First Seen: 2026-09-29 Asserted:
Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)
Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today's update for the current "27" branch does not address security issues, but fixes some functional issues that got caught after the release two weeks ago. A 27. 1 version was also expected to support the new foldable iPhone and will likely include specific features geared to the soon to be available device.
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the
You've reached the end of current stories for this search.
