Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Attacks
Share
Apple has released security updates for iOS and macOS to patch a zero-day vulnerability that has been exploited in highly sophisticated, targeted attacks.
The flaw, tracked as CVE-2026-86950, is an out-of-bounds write issue within the CoreGraphics component. This component is responsible for 2D graphics and PDF rendering across the operating system.
An attacker could achieve arbitrary code execution by processing a specially crafted file. While Apple has not specified the exact delivery method, the involvement of CoreGraphics suggests the vulnerability could be triggered via web pages, email attachments, or messaging applications through automatic link or attachment previews.
Apple stated that the company became aware of the issue through Meta’s product security team. The tech giant noted that the vulnerability may have been used in “extremely sophisticated” attacks against specific individuals running versions of iOS prior to iOS 27.
Affected Software and Available Patches
The vulnerability impacts several Apple operating systems. To mitigate the risk, users should update to the following versions:
- iOS 26.7.1
- iPadOS 26.7.1
- macOS Tahoe 26.7.1
- macOS Sequoia 15.8.1
Although both mobile and desktop systems are vulnerable, Apple’s advisory indicates that observed exploitations have been limited to iOS. The latest releases, iOS 27 and macOS Golden Gate 27, do not appear to be affected.
The CISA Known Exploited Vulnerabilities catalogue has not yet added this specific CVE, though this marks the ninth Apple product flaw included in the catalogue this year.
Users are advised to install the latest security updates immediately to protect against further exploitation.




Leave a Reply