Apple patches exploited CoreGraphics zero-day (CVE-2026-86950)
Apple shipped iOS/iPadOS 26.7.1 and macOS 15.8.1/26.7.1 for CVE-2026-86950, a CoreGraphics out-of-bounds write used in targeted attacks and reported by Meta.
Apple has patched CVE-2026-86950, an out-of-bounds write in CoreGraphics that it says "may have been exploited in an extremely sophisticated attack against specific targeted individuals." Processing a maliciously crafted file can trigger arbitrary code execution. Update now if you manage Apple fleets, and prioritize anyone plausibly worth a targeted operation.
The fixes shipped September 28. Apple credited Meta Product Security with the report — an unusual reporter for an Apple in-the-wild bug, and a signal the flaw surfaced through active-attack telemetry rather than routine research.
Affected and fixed
Per Apple's advisories (bulletins 149226, 149228, 149229) and CERTFR-2026-AVI-1236:
- iOS / iPadOS — fixed in 26.7.1. Devices from iPhone 11 and later, iPad Pro (3rd-gen 12.9″ / 1st-gen 11″ and later), iPad Air (3rd-gen+), iPad (8th-gen+), iPad mini (5th-gen+).
- macOS Tahoe — fixed in 26.7.1.
- macOS Sequoia — fixed in 15.8.1.
The CVE is tracked at NVD. CoreGraphics is the framework that parses and renders images and PDFs, so the attack surface is any code path that opens attacker-supplied media — messaging previews, mail attachments, documents.
Exploitation status
Apple's wording is its standard formula for confirmed in-the-wild abuse: it is "aware of a report that this issue may have been actively exploited." The company scoped it to "specific targeted individuals" on versions before iOS 27, which reads as a targeted-implant delivery chain rather than opportunistic mass exploitation. Apple has published no IOCs, and no vendor or research team has attributed the activity to a named operator. We won't invent one.
Meta's involvement is the notable detail: platform security teams increasingly catch mobile zero-days through their own abuse detection, then hand the artifact to the OS vendor. That is how several recent CoreGraphics and ImageIO parsing bugs have come to light.
Action checklist
- Push iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 through MDM now. Force-install, don't wait for user opt-in.
- Prioritize high-risk users first — executives, journalists, activists, anyone plausibly targeted. Enable Lockdown Mode on those devices.
- Confirm coverage: older iPhones (pre-11) and unsupported iPads don't get this fix. Retire or isolate them.
- There are no published IOCs, so detection is limited to patch-state auditing. Track which devices are still below 26.7.1 / 15.8.1 and chase them.
Context
This is another CoreGraphics/media-parsing zero-day used against a narrow target set and reported by a platform security team rather than a lone researcher — the same shape as the ImageIO and CoreGraphics bugs Apple has rushed out in prior cycles. The delivery vector keeps coming back to a single truth for defenders: on Apple platforms, the file-parsing path is the one that gets weaponized against the people most worth attacking.