Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks
Brief
Apple patched zero-day CVE-2026-86950 in CoreGraphics, exploited in sophisticated targeted attacks against specific iOS users.
Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when the system processes a specially crafted file.
The vulnerability affects iOS 26. 7 and earlier versions before iOS 27, as well as iPadOS 26. 7 and earlier and supported versions of macOS Tahoe and macOS Sequoia. Apple released iOS 26.
- 1, iPadOS 26.
- 1, macOS Tahoe 26.
- 1 and macOS Sequoia 15.
- 1 to address the issue.
“Processing a maliciously crafted file may lead to arbitrary code execution.
