Apple patches CoreGraphics zero-day CVE-2026-86950 exploited in targeted attacks
Apple has fixed an out-of-bounds write in Core Graphics that could give code execution from a malicious file. Apple says it may have been used in an "extremely sophisticated attack" on specific individuals, and CISA has added it to KEV.
Key Takeaways
- CVE-2026-86950 is an out-of-bounds write in Apple's Core Graphics framework. Processing a maliciously crafted file can lead to arbitrary code execution.
- Apple says the flaw may have been exploited in an "extremely sophisticated attack against specific targeted individuals". Meta Product Security reported it.
- CISA added the CVE to its Known Exploited Vulnerabilities (KEV) catalogue on 29 September. Treat it as an emergency patch, not routine maintenance.
- Fixes shipped in iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, so any fleet still on an earlier build is exposed.
What happened
Apple has patched CVE-2026-86950, a memory-corruption flaw in the Core Graphics framework. According to Help Net Security, the bug is an out-of-bounds write. An attacker who gets a vulnerable device to process a maliciously crafted file can use it to execute arbitrary code.
Apple's advisory says it is aware of a report that the issue may have been exploited in an "extremely sophisticated attack against specific targeted individuals". The report credits Meta Product Security. CISA added the vulnerability to the KEV catalogue on 29 September.
Fixed versions
- iOS 26.7.1 and iPadOS 26.7.1
- macOS Tahoe 26.7.1
- macOS Sequoia 15.8.1
Why it matters
Core Graphics is a foundational rendering layer. Image and document parsing sits behind many everyday features: messaging previews, mail, browsers and file viewers. A bug that triggers on a crafted file is therefore a plausible delivery route for targeted spyware-style operations. We have not seen a public technical write-up of the exact trigger or delivery path for this CVE, so we won't speculate about either.
The exploitation profile is the more useful signal for defenders. Apple's wording ("specific targeted individuals") and the report coming from a platform security team both point to narrowly aimed use rather than mass exploitation. That does not make it a low priority. Exploits like this tend to be reused and adapted once a patch is public, because patch diffing narrows the search for the bug.
What defenders should do
- 1Patch now. Push the 26.7.1 and 15.8.1 releases through MDM. Prioritise executives, journalists, administrators, and anyone else likely to be targeted.
- 2Check your inventory. Find devices stuck on earlier builds, including unmanaged personal devices that access corporate data.
- 3Use the KEV listing as a trigger. If your vulnerability SLAs key off KEV status, this entry should start the clock for Apple endpoints.
- 4Offer a high-risk user option. For people who may be targeted, consider Apple's Lockdown Mode and a clear route for reporting suspicious behaviour, such as unexpected crashes or battery drain.
What we can and cannot say
Apple has not published details of the attackers, the victims, or the exploit chain, and neither have we verified any. Apple describes the exploitation as "may have been" rather than confirmed, so treat the attribution and scope as open. Updating the OS is what closes the exposure, whatever the eventual post-mortem says.
Frequently Asked Questions
What is CVE-2026-86950?
It is an out-of-bounds write vulnerability in Apple's Core Graphics framework. Processing a maliciously crafted file can lead to arbitrary code execution. Apple says it may have been exploited in an extremely sophisticated attack against specific targeted individuals.
Which Apple updates fix CVE-2026-86950?
The fixes ship in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Check Apple's security releases page for the full list of affected and fixed products.
Should ordinary users be worried?
Apple describes the exploitation as targeted, not widespread. Even so, the CVE is in CISA's KEV catalogue, so everyone should install the update promptly. Updating is the only reliable mitigation.
Sources
- 1Apple squashes zero-day bug exploited in "extremely sophisticated" attack (CVE-2026-86950) — Help Net Security
- 2Known Exploited Vulnerabilities Catalog — CISA
- 3Apple security releases — Apple