Apple patches CoreGraphics zero-day already exploited in targeted attacks
Article excerpt
security Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file Apple has patched a CoreGraphics zero-day after warning that attackers may already have used the bug to compromise a small number of carefully chosen targets. The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write flaw in CoreGraphics, Apple's framework for handling graphics across its operating systems. According to Apple's advisory, processing a maliciously crafted file could allow an attacker to execute arbitrary code on a vulnerable device. The fruity vendor said it addressed the problem with improved bounds checking, though the bug appears to have made it out into the wild before Apple could squash it. "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27," the company said. As is customary when Cupertino encounters the sort of security bug somebody has apparently found useful, further details are thin on the ground. Apple didn't say who was targeted, how many people were affected, who was behind the attacks, or exactly how the vulnerability was being exploited. However, its choice of words suggests this wasn't a bug being exploited indiscriminately across the internet, and raises the possibility that it was used as part of a...
Keep reading with a free account
The rest of this article, and every signal for Apple, is in your free account.
Extracted from this sentence
The fix landed on Monday in iOS 26.7.1 and iPadOS 26.7.1.
