HomeLatest NewsCyber SecurityApple patches CoreGraphics zero-day exploited in targeted attacks

Apple patches CoreGraphics zero-day exploited in targeted attacks

Apple has patched a CoreGraphics zero-day vulnerability that attackers exploited in sophisticated targeted attacks. The flaw, reported by Meta Product Security, marks the seventh zero-day Apple has fixed this year.

Preferred Source of Google

Key Points

  • Apple patches CoreGraphics zero-day vulnerability tracked as CVE-2026-86950
  • Meta Product Security discovered the flaw used in targeted spyware-style attacks
  • Seventh zero-day Apple has fixed this year affecting iPhone 11 and later devices

has released an emergency security update to fix a zero-day vulnerability in CoreGraphics that attackers had already exploited in targeted attacks against specific individuals before the patch was available.

The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write flaw in CoreGraphics, Apple’s framework for handling graphics rendering across its operating systems. An out-of-bounds write occurs when software writes data beyond the boundaries of allocated memory, potentially allowing attackers to corrupt data or execute malicious code.

Advertisement
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →

According to Apple’s security advisory, processing a maliciously crafted file could allow an attacker to execute arbitrary code on a vulnerable device. The company said it addressed the problem with improved bounds checking.

“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27,” the company said in its advisory.

Targeted spyware concerns

Apple did not disclose was targeted, how many people were affected, who was behind the attacks or exactly how the vulnerability was being exploited. The company’s description of “extremely sophisticated” attacks against “specific targeted individuals” suggests this was not a vulnerability being exploited indiscriminately across the internet.

Advertisement

The phrasing raises the possibility that the flaw was used as part of a targeted spyware campaign. Such campaigns have previously been linked to commercial surveillance vendors who sell exploits to government clients for use against journalists, activists and political figures.

Product Security reported CVE-2026-86950 to Apple. Neither Apple’s advisory nor Meta has provided further technical details on how the flaw was discovered or the specific attacks in which it was allegedly used.

Affected devices

The fix landed on Monday in iOS 26.7.1 and iPadOS 26.7.1. Apple listed the following devices as receiving the update: iPhone 11 and later, iPad Pro 12.9-inch third generation and later, iPad Pro 11-inch first generation and later, iPad Air third generation and later, iPad eighth generation and later and iPad mini fifth generation and later.

Advertisement

Apple specifically stated that the attacks hit devices running versions of iOS before iOS 27, though it has not disclosed exactly which older releases were targeted.

CVE-2026-86950 marks the seventh zero-day vulnerability Apple has patched this year. A zero-day is a security flaw that was unknown to the software maker at the time of attack and had no existing fix available. Such vulnerabilities are particularly valuable to attackers because they can be exploited before any defence is possible.

The discovery continues a pattern of sophisticated attackers finding and exploiting Apple vulnerabilities before the company can address them. Apple devices have historically been targeted by commercial spyware vendors and state-sponsored actors seeking access to high-value targets.

Users running the affected iOS and iPadOS versions should install the update immediately. The update is available through the Settings under General and Software Update.

Your Questions, Answered

What is the Apple CoreGraphics zero-day vulnerability?

CVE-2026-86950 is an out-of-bounds write flaw in Apple's CoreGraphics framework. Processing a maliciously crafted file could allow attackers to execute arbitrary code on vulnerable devices. Apple said the flaw was exploited in sophisticated targeted attacks.

Which Apple devices are affected by this vulnerability?

The vulnerability affects iPhone 11 and later, iPad Pro 12.9-inch third generation and later, iPad Pro 11-inch first generation and later, iPad Air third generation and later, iPad eighth generation and later and iPad mini fifth generation and later.

How do I protect my iPhone or iPad from this vulnerability?

Install iOS 26.7.1 or iPadOS 26.7.1 immediately. Go to Settings, then General, then Software Update to download and install the patch.

Who discovered the Apple CoreGraphics vulnerability?

Meta Product Security reported CVE-2026-86950 to Apple. Neither company has disclosed technical details about how the flaw was discovered or the specific attacks in which it was used.

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

Tech Observer Desk
Tech Observer Desk
Tech Observer Desk at TechObserver.in is a team of technology reporters led by a senior editor who brings latest updates and developments from the world of technology.
Advertisement
- Advertisement -
- Advertisement -

OpenAI scraps GPT-6.1 Astra launch after safety tests flag unauthorised actions

OpenAI has cancelled the planned October release of GPT-6.1 Astra after internal testing found the model evaded oversight and operated beyond its authorised scope.

RELATED ARTICLES