Apple patches CVE-2026-86950 in CoreGraphics
Apple fixed CVE-2026-86950 in iOS, iPadOS, and macOS. The CoreGraphics flaw may have been used in highly sophisticated attacks.
Apple released updates for iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1 to fix CVE-2026-86950, an out-of-bounds write flaw in CoreGraphics. The company said it was aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific individuals on versions earlier than iOS 27.
Apple released patches for iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1, and macOS Tahoe 26.7.1 to fix CVE-2026-86950, an out-of-bounds write flaw in CoreGraphics. The company said it was aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific individuals on versions earlier than iOS 27.
What did Apple fix?
Apple said the vulnerability was addressed with improved bounds checks. The CVE entry says a maliciously crafted file can lead to arbitrary code execution when the system processes that content.
The technical reference points to CoreGraphics, the framework used by iOS and macOS to render and manipulate 2D graphics. SecurityWeek reported that Apple credited Meta's product security team with the initial report. Help Net Security also said Meta Product Security reported the flaw, and that Apple did not share additional details about the attacks or the people affected.
Which devices does it affect?
The iOS and iPadOS updates apply to iPhone 11 and later, 12.9-inch iPad Pro third generation and later, 11-inch iPad Pro first generation and later, iPad Air third generation and later, iPad eighth generation and later, and iPad mini fifth generation and later, according to The Register.
The Canadian Centre for Cyber Security also said CISA added CVE-2026-86950 to the Known Exploited Vulnerabilities catalog on September 29, 2026. That is an official confirmation from a foreign government CERT, although it does not replace direct verification of the CISA record.
Dark Reading also reported the KEV listing and placed the affected component within the framework iOS and macOS use for 2D graphics. At the same time, Apple said it was aware of a report linking the flaw to an extremely sophisticated attack against specific targets, but it offered no further public details on the real scope of exploitation.
Sources
- About the security content of iOS 26.7.1 and iPadOS 26.7.1support.apple.com· Apple Support
- Apple patches CoreGraphics zero-day already exploited in targeted attackstheregister.com· The Register
- CVE-2026-86950 - CVE Recordcve.mitre.org· MITRE CVE
- Apple security advisory (AV26-971)cyber.gc.ca· Canadian Centre for Cyber Security
- CVE-2026-86950 - Vulnerability Detailsapp.opencve.io· OpenCVE
- Apple Zero-Day Vulnerability Weaponized in Targeted Attacksdarkreading.com· Dark ReadingUnverified URL
- Apple Warns Users iOS Vulnerability Exploited in Attack (CVE-2026-86950)threatprotect.qualys.com· Qualys ThreatProtect
- Apple Patches Zero-Day Linked to 'Extremely ...'securityweek.com· SecurityWeek
- Apple squashes zero-day bug exploited in "extremely ..."helpnetsecurity.com· Help Net Security



