Apple Patches CoreGraphics Zero-Day Flaw Exploited in Targeted Attacks
Share
Apple has released urgent security updates to address a zero-day vulnerability in its CoreGraphics framework that is being actively exploited in highly sophisticated, targeted attacks.
The vulnerability, tracked as CVE-2026-20700, involves an out-of-bounds write weakness discovered by Meta Product Security. This flaw affects several Apple operating systems, including iOS, iPadOS, macOS, watchOS, and tvOS.
Technical Impact of CoreGraphics Flaw
CoreGraphics is a critical framework used across Apple’s ecosystem for two-dimensional vector graphics, image rendering, and text drawing. The out-of-bounds write issue allows attackers to write data outside of the allocated memory buffer.
Apple warned that processing a maliciously crafted file could lead to arbitrary code execution (ACE). Successful exploitation can also allow an attacker to crash a program or corrupt data on the target device. The company noted that the issue may have been used in sophisticated attacks against specific, targeted individuals on versions of iOS prior to iOS 27.
Affected Devices and Required Updates
The impact is widespread, affecting a variety of hardware including iPhone 11 and later, several iPad Pro, Air, and mini models, and Macs running macOS Sequoia or macOS Tahoe. While the exploitation appears limited to highly targeted scenarios, users are strongly advised to install the following security updates immediately:
- iOS 26.7.1
- iPadOS 26.7.1
- macOS Tahoe 26.7.1
- macOS Sequoia 15.8.1
This marks the second zero-day vulnerability exploited in the wild that Apple has addressed in 2026. Earlier in February, the company patched an arbitrary code execution vulnerability in dyld, the Dynamic Link Editor used by Apple operating systems.




Leave a Reply