Skip to main content
Emerging ThreatsMalware & Ransomware

Apple Fixes CoreGraphics Flaw Targeted in Sophisticated Attacks

Modern smartphone on a clean surface with a blurred background and a hint of a document nearby.

"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27," the company said.

CVE-2026-86950: an out-of-bounds write in CoreGraphics

Apple disclosed a vulnerability tracked as CVE-2026-86950, describing it as an out-of-bounds write in the CoreGraphics component that "could lead to arbitrary code execution when processing a maliciously crafted file." The vendor said the flaw was fixed by implementing improved bounds checking. Beyond that technical summary, Apple warned the flaw "may have been exploited in targeted attacks" but did not provide operational details about those incidents.

Which systems received fixes and which devices are listed

Apple published specific updates to address the issue. The fixes are included in:

  • iOS 26.7.1 and iPadOS 26.7.1 — applying to iPhone 11 and later; iPad Pro 12.9-inch 3rd generation and later; iPad Pro 11-inch 1st generation and later; iPad Air 3rd generation and later; iPad 8th generation and later; and iPad mini 5th generation and later.
  • macOS Tahoe 26.7.1 — for Macs running macOS Tahoe.
  • macOS Sequoia 15.8.1 — for Macs running macOS Sequoia.

Those version numbers are the releases Apple named as containing the corrected CoreGraphics code paths.

Meta Product Security reported the issue

Apple credited Meta Product Security with the discovery and reporting of CVE-2026-86950. That acknowledgement appears in Apple’s advisory alongside the description of the fix and the note about potential targeted exploitation.

Recent pattern: a prior, weaponized dyld vulnerability

The CoreGraphics advisory followed an earlier fix this February. In February, Apple addressed a memory corruption problem in dyld tracked as CVE-2026-20700 (CVSS score: 7.8) and said that issue "had been weaponized in sophisticated cyber attacks." The two advisories taken together underscore that Apple has recently remedied multiple flaws the company characterizes as being used in high-end or targeted operations.

How technologists, enterprises, and end users are likely to respond

  • Technologists and security teams — They will prioritize deploying the listed updates (iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1) to assets that match the specified device models and OS versions and will review CoreGraphics usage in their threat models because the flaw could allow arbitrary code execution when handling malicious files.
  • Enterprises and procurement leaders — Fleet owners will map which corporate devices match the listed device families (for example, iPhone 11 and later, the named iPad models, and Macs running the specified macOS releases) and schedule patch windows to ensure devices receive the vendor-supplied mitigations.
  • End users and the general public — Users of the named platforms will be directed to install the updates Apple released; the advisory explicitly identifies the OS releases that contain the corrections and the device models to which those releases apply.

Apple’s advisory is clear about the technical flaw, the fixes, and the party credited with reporting it. It is equally clear about one other point: the company provided no specifics on how many individuals were targeted, whether any of the exploitation attempts succeeded, or when the first instance of CVE-2026-86950 exploitation occurred. That absence—coupled with an earlier, explicitly weaponized dyld vulnerability in February—leaves defenders with both a patch to deploy and a set of unanswered operational questions about the scope and timing of the alleged targeted activity.

Original story