CVE-2026-20700 and CoreGraphics
Apple released security updates to remediate a zero-day vulnerability tracked as CVE-2026-20700 that stems from an out-of-bounds write weakness in CoreGraphics, the company framework used for two-dimensional vector graphics, image rendering, and text drawing across its platforms. Meta Product Security discovered the vulnerability, the company said, and Apple warned that the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27."
How the vulnerability works and why it matters
Out-of-bounds write vulnerabilities occur when code writes data outside the bounds of an allocated memory buffer. Apple described the practical consequences in plain terms: successful exploitation can let attackers "crash a program, corrupt data, or, in the worst case, gain remote code execution by writing data outside the allocated memory buffer." Apple added that "processing a maliciously crafted file may lead to arbitrary code execution."

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhich devices and updates are affected
The update applies broadly across older and newer Apple models. Apple named the impacted product families explicitly:
- iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
- Macs running macOS Sequoia 15.8.1 and Tahoe 26.7.1
Apple said it has addressed the issue with "improved bounds checking" in iOS 26.7.1 and iPadOS 26.7.1, and in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, and strongly advised that users install these security updates promptly to prevent potential ongoing attacks.
How this fits into Apple’s recent patch cadence
Apple framed the CoreGraphics patch as the latest in a run of fixes for vulnerabilities exploited in the wild. The company said this patch brings the count to two zero-days fixed since the start of the year. Apple noted another arbitrary code execution vulnerability in dyld — the Dynamic Link Editor used by Apple operating systems — that it also described as "exploited in extremely sophisticated targeted attacks" and said was patched in February. The company additionally called out earlier work this year and last: a high-severity Beats Studio Buds flaw (CVE-2025-20701) allowing attackers in Bluetooth range to spy on conversations; fixes for older iPhones and iPads against four vulnerabilities exploited in cyberespionage and crypto-theft by the Coruna exploit kit; and seven zero-days addressed in 2025 with identifiers CVE-2025-24085, CVE-2025-24200, CVE-2025-24201, CVE-2025-31200, CVE-2025-31201, CVE-2025-43529, and CVE-2025-14174.
What this means for security teams, enterprises, and end users
- Technologists and security teams: Patch management moves to the front of the calendar. With Apple attributing exploitation to “extremely sophisticated” targeted attacks, teams will need to verify deployment of iOS 26.7.1, iPadOS 26.7.1, and the macOS Tahoe/Sequoia releases across device fleets and confirm that system inventories include the listed models.
- Affected enterprises and procurement leaders: The impact spans devices sold across multiple product generations. Procurement and asset teams should reconcile device models in use against the explicit list Apple published and consider expedited patch windows for users handling sensitive data or who may be potential targets of targeted attacks.
- End users and the general public: Apple’s notice is direct: a maliciously crafted file could lead to arbitrary code execution. Users on the affected device models are urged to install the listed updates as soon as practical to prevent potential ongoing exploitation.
Apple’s public advisory makes two things clear: the vulnerability is concrete (an out-of-bounds write in CoreGraphics discovered by Meta Product Security), and the remedy is already available across current Apple update channels. The company’s succinct, repeated emphasis that the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals" frames this as a targeted threat rather than a mass-campaign risk — yet the remedy it offers is the same for all users: install the updates that implement "improved bounds checking."




