Apple fixes CoreGraphics zero-day CVE-2026-86950
Apple has shipped security updates for a zero-day vulnerability in CoreGraphics that was exploited in what the company describes as "extremely sophisticated" attacks against iOS users.
The flaw, tracked as CVE-2026-86950, was reported by Meta Product Security. It is an out-of-bounds write bug in CoreGraphics, the framework Apple uses for two-dimensional vector graphics, image rendering and text drawing. The framework is shared across iOS, macOS, iPadOS, watchOS and tvOS.
A crafted file is enough
Out-of-bounds write bugs happen when a program writes data outside the memory buffer it was given. Depending on how they are exploited, they can crash an application, corrupt data or, in the worst case, let an attacker run code remotely.
In its advisory published on Monday, Apple said the bug can be triggered by processing a malicious file.
"Processing a maliciously crafted file may lead to arbitrary code execution. An out-of-bounds write issue was addressed with improved bounds checking," the company explained.
Apple also confirmed that the flaw had been used in the wild.
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27," it said.
The company did not share details about the attacks, the targets or who may be behind them.
Affected devices and fixed versions
The list of affected hardware covers both older and newer models:
- iPhone 11 and later
- iPad Pro 12.9-inch 3rd generation and later
- iPad Pro 11-inch 1st generation and later
- iPad Air 3rd generation and later
- iPad 8th generation and later
- iPad mini 5th generation and later
- Macs running macOS Sequoia and macOS Tahoe
The fix, which adds improved bounds checking, is included in iOS 26.7.1 and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
Although the attacks appear to have been narrowly targeted, users are advised to install the updates as soon as possible to block any ongoing exploitation.
Apple's zero-day tally
CVE-2026-86950 is the second Apple zero-day exploited in the wild that has been patched since the start of 2026. The first, CVE-2026-20700, was an arbitrary code execution flaw in dyld, the Dynamic Link Editor used by Apple's operating systems. It was fixed in February and was also used in extremely sophisticated targeted attacks.
Apple has addressed other notable issues this year as well. It fixed a high-severity flaw in Beats Studio Buds (CVE-2025-20701) that let attackers within Bluetooth range listen in on users' conversations. It also patched older iPhones and iPads against four vulnerabilities that were abused in cyberespionage and crypto-theft attacks using the Coruna exploit kit.
In 2025, the company fixed seven zero-days exploited in the wild:
- CVE-2025-24085 in January
- CVE-2025-24200 in February
- CVE-2025-24201 in March
- CVE-2025-31200 and CVE-2025-31201 in April
- CVE-2025-43529 and CVE-2025-14174 in December
Our Take
For most iPhone and Mac owners, the practical advice is simple: update now. The attacks described by Apple look like the kind reserved for a small number of high-value targets, but once a patch is public, the underlying bug becomes easier for others to study. That can widen the pool of potential attackers over time.
The file-based trigger is worth noting. A flaw in a core rendering framework like CoreGraphics can potentially be reached through many different apps that display images or documents. This suggests why such components remain attractive to well-resourced attackers. The "extremely sophisticated" wording and the focus on "specific targeted individuals" follow a familiar pattern in Apple's advisories, which in the past has often pointed to commercial spyware or state-backed operations. Apple has not said who was behind this campaign, so that link remains speculation.
The pace of in-the-wild exploitation also matters. Two Apple zero-days so far in 2026 is fewer than the seven fixed last year, but Apple platforms are clearly not a safe harbor. Mac users in particular face a mix of targeted exploits and commodity threats, such as the MacSync malware that recently abused iCloud calendars. Across the industry, attackers keep moving quickly from disclosure to exploitation, as seen with the Citrix NetScaler flaw now under mass attack.
It is worth watching whether Meta or other researchers publish more technical detail on how CVE-2026-86950 was delivered, and whether Apple extends fixes to older devices that did not receive them in this round. Organisations managing Apple fleets should confirm that devices are actually running the patched versions rather than assuming automatic updates have taken care of it.
