Skip to main content
AppleLaunch

Apple patches CoreGraphics zero-day already exploited in targeted attacks

What happened

Apple released security patches for a CoreGraphics zero-day vulnerability in iOS 26.7.1 and iPadOS 26.7.1.

Source

Article excerpt

security Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file Apple has patched a CoreGraphics zero-day after warning that attackers may already have used the bug to compromise a small number of carefully chosen targets. The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write flaw in CoreGraphics, Apple's framework for handling graphics across its operating systems. According to Apple's advisory, processing a maliciously crafted file could allow an attacker to execute arbitrary code on a vulnerable device. The fruity vendor said it addressed the problem with improved bounds checking, though the bug appears to have made it out into the wild before Apple could squash it. "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27," the company said. As is customary when Cupertino encounters the sort of security bug somebody has apparently found useful, further details are thin on the ground. Apple didn't say who was targeted, how many people were affected, who was behind the attacks, or exactly how the vulnerability was being exploited. However, its choice of words suggests this wasn't a bug being exploited indiscriminately across the internet, and raises the possibility that it was used as part of a...

Keep reading with a free account

The rest of this article, and every signal for Apple, is in your free account.

Extracted from this sentence

The fix landed on Monday in iOS 26.7.1 and iPadOS 26.7.1.

Extracted by Autobound

From the Signal API record
Event
Launch

What this signalsA launch often needs new go-to-market and support spend.

Product
iOS 26.7.1 and iPadOS 26.7.1
Takes effect
Sep 28, 2026

The full record

From the Signal API record

Details

Release type
Update

Topics and mentions

Product tags

  • online technology
  • general technology
  • mobile
  • security

Extraction

Confidence
90%
Detected
Sep 29, 2026
signal_type
news
signal_subtype
launches

Use this data

Get every launch signal for Apple and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Apple this week?”

  2. Send it to your own tools

    The Signal API returns launch signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/cd383b38-87fa-9400-d992-1b7517e1456b returns this record as JSON. POST /v1/companies/enrich returns every signal for apple.com.

{
  "signal_id": "cd383b38-87fa-9400-d992-1b7517e1456b",
  "signal_type": "news",
  "signal_subtype": "launches",
  "detected_at": "2026-09-29T14:30:00+00:00",
  "company": {
    "name": "Apple",
    "domain": "apple.com"
  },
  "data": {
    "url": "https://www.theregister.com/security/2026/09/29/apple-patches-coregraphics-zero-day-already-exploited-in-targeted-attacks/5299721",
    "title": "Apple patches CoreGraphics zero-day already exploited in targeted attacks",
    "excerpt": "security Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file Apple has patched a CoreGraphics zero-day after warning that attackers may already have used the bug to compromise a small number of carefully chosen targets. The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write flaw in CoreGraphics, Apple's framework for handling graphics across its operating systems. According to Apple's advisory, processing a maliciously crafted file could allow an attacker to execute arbitrary code on a vulnerable device. The fruity vendor said it addressed the problem with improved bounds checking, though the bug appears to have made it out into the wild before Apple could squash it. \"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27,\" the company said. As is customary when Cupertino encounters the sort of security bug somebody has apparently found useful, further details are thin on the ground. Apple didn't say who was targeted, how many people were affected, who was behind the attacks, or exactly how the vulnerability was being exploited. However, its choice of words suggests this wasn't a bug being exploited indiscriminately across the internet, and raises the possibility that it was used as part of a...",
    "product": "iOS 26.7.1 and iPadOS 26.7.1",
    "summary": "Apple released security patches for a CoreGraphics zero-day vulnerability in iOS 26.7.1 and iPadOS 26.7.1.",
    "planning": false,
    "image_url": "https://image.theregister.com/5299734.jpg?imageId=5299734&x=0&y=12.35&cropw=100&croph=77.71&panox=0&panoy=12.35&panow=100&panoh=77.71&width=1200&height=683",
    "confidence": 0.9,
    "product_data": {
      "name": "iOS 26.7.1 and iPadOS 26.7.1",
      "full_text": "iOS 26.7.1 and iPadOS 26.7.1",
      "fuzzy_match": false,
      "release_type": "update"
    },
    "product_tags": [
      "online_technology",
      "general_technology",
      "mobile",
      "security"
    ],
    "published_at": "2026-09-29T14:30:00Z",
    "effective_date": "2026-09-28",
    "article_sentence": "The fix landed on Monday in iOS 26.7.1 and iPadOS 26.7.1."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.