Apple Patches iPhone CoreGraphics Flaw Allowing Arbitrary Code Execution
Brief
Apple has released iOS 26.
- 1 and iPadOS 26.
- 1 to address CVE-2026-86950, a CoreGraphics memory-corruption vulnerability that could allow arbitrary code execution when a device processes a maliciously crafted file.
The flaw may have been exploited in an “extremely sophisticated attack” targeting specific individuals on iOS versions released before iOS 27.
Released on September 28, 2026, the security update fixes an out-of-bounds write in CoreGraphics, Apple’s graphics-rendering framework used throughout iOS and iPadOS to process visual and document-related content.
Apple Patches iPhone CoreGraphics Flaw
Tracked as CVE-2026-86950, the bug exists in how CoreGraphics handles certain attacker-controlled file data. An out-of-bounds write occurs when software writes data outside its allocated memory region.
