Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Ravie LakshmananSep 28, 2026Vulnerability / Endpoint Security

Apple has recently released security updates to fix a vulnerability found in older versions of iOS, iPadOS, and macOS that may have been exploited in targeted attacks.

The vulnerability, known as CVE-2026-86950, involves an out-of-bounds write affecting the CoreGraphics component, potentially leading to arbitrary code execution when processing a maliciously crafted file.

Apple has addressed the issue with enhanced bounds checking, giving credit to Meta Product Security for identifying and reporting the problem.

“Apple has received reports that this vulnerability could have been used in a highly sophisticated attack against specific individuals using iOS versions before iOS 27,” Apple stated.

However, Apple did not disclose the number of individuals targeted, the success rate of these attempts, or when the first exploitation of CVE-2026-86950 occurred.

The fix has been implemented in the following devices and operating system versions –

  • iOS 26.7.1 and iPadOS 26.7.1 – compatible with iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
  • macOS Tahoe 26.7.1 – for Macs running macOS Tahoe
  • macOS Sequoia 15.8.1 – for Macs running macOS Sequoia

In a separate incident earlier this year, Apple fixed a memory corruption issue in dyld (CVE-2026-20700, CVSS score: 7.8) that had been exploited in advanced cyber attacks.