Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

MediumThe Hacker News · info@thehackernews.com (The Hacker News)·

At a glance

Severity
Medium
Used in attacks
No flaws named
Vendors and products
AppleiOS
Reported by
1 outlet

Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks.

The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file.

The iPhone maker said the issue was addressed with improved bounds checking. It credited Meta Product Security with discovering and reporting the issue.

"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27," it added.

However, the company offered no details on how many individuals were targeted, if any of those attempts were successful, or when the first instance of CVE-2026-86950 exploitation occurred.

The shortcoming has been addressed in the following devices and operating system versions -

  • iOS 26.7.1 and iPadOS 26.7.1 - iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
  • macOS Tahoe 26.7.1 - Macs running macOS Tahoe
  • macOS Sequoia 15.8.1 - Macs running macOS Sequoia

Earlier this February, Apple addressed a memory corruption issue in dyld (CVE-2026-20700, CVSS score: 7.8) that it said had been weaponized in sophisticated cyber attacks.

Reproduced in full under licence from The Hacker News. © The Hacker News. Written by info@thehackernews.com (The Hacker News).

Fastnexa security experts

Dealing with this in your own company?

If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.

Book a 30-min callWhatsApp us

Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →

Coverage

One outlet has carried this so far.

  1. The Hacker News ↗Established SourceFirst reported

    2026-09-28 19:18 UTC

Related stories