Key Points
- Apple patches CoreGraphics zero-day vulnerability tracked as CVE-2026-86950
- Meta Product Security discovered the flaw used in targeted spyware-style attacks
- Seventh zero-day Apple has fixed this year affecting iPhone 11 and later devices
Apple has released an emergency security update to fix a zero-day vulnerability in CoreGraphics that attackers had already exploited in targeted attacks against specific individuals before the patch was available.
The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write flaw in CoreGraphics, Apple’s framework for handling graphics rendering across its operating systems. An out-of-bounds write occurs when software writes data beyond the boundaries of allocated memory, potentially allowing attackers to corrupt data or execute malicious code.
According to Apple’s security advisory, processing a maliciously crafted file could allow an attacker to execute arbitrary code on a vulnerable device. The company said it addressed the problem with improved bounds checking.
“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27,” the company said in its advisory.
Targeted spyware concerns
Apple did not disclose who was targeted, how many people were affected, who was behind the attacks or exactly how the vulnerability was being exploited. The company’s description of “extremely sophisticated” attacks against “specific targeted individuals” suggests this was not a vulnerability being exploited indiscriminately across the internet.
The phrasing raises the possibility that the flaw was used as part of a targeted spyware campaign. Such campaigns have previously been linked to commercial surveillance vendors who sell exploits to government clients for use against journalists, activists and political figures.
Meta Product Security reported CVE-2026-86950 to Apple. Neither Apple’s advisory nor Meta has provided further technical details on how the flaw was discovered or the specific attacks in which it was allegedly used.
Affected devices
The fix landed on Monday in iOS 26.7.1 and iPadOS 26.7.1. Apple listed the following devices as receiving the update: iPhone 11 and later, iPad Pro 12.9-inch third generation and later, iPad Pro 11-inch first generation and later, iPad Air third generation and later, iPad eighth generation and later and iPad mini fifth generation and later.
Apple specifically stated that the attacks hit devices running versions of iOS before iOS 27, though it has not disclosed exactly which older releases were targeted.
CVE-2026-86950 marks the seventh zero-day vulnerability Apple has patched this year. A zero-day is a security flaw that was unknown to the software maker at the time of attack and had no existing fix available. Such vulnerabilities are particularly valuable to attackers because they can be exploited before any defence is possible.
The discovery continues a pattern of sophisticated attackers finding and exploiting Apple vulnerabilities before the company can address them. Apple devices have historically been targeted by commercial spyware vendors and state-sponsored actors seeking access to high-value targets.
Users running the affected iOS and iPadOS versions should install the update immediately. The update is available through the Settings app under General and Software Update.
Your Questions, Answered
What is the Apple CoreGraphics zero-day vulnerability?
CVE-2026-86950 is an out-of-bounds write flaw in Apple's CoreGraphics framework. Processing a maliciously crafted file could allow attackers to execute arbitrary code on vulnerable devices. Apple said the flaw was exploited in sophisticated targeted attacks.
Which Apple devices are affected by this vulnerability?
The vulnerability affects iPhone 11 and later, iPad Pro 12.9-inch third generation and later, iPad Pro 11-inch first generation and later, iPad Air third generation and later, iPad eighth generation and later and iPad mini fifth generation and later.
How do I protect my iPhone or iPad from this vulnerability?
Install iOS 26.7.1 or iPadOS 26.7.1 immediately. Go to Settings, then General, then Software Update to download and install the patch.
Who discovered the Apple CoreGraphics vulnerability?
Meta Product Security reported CVE-2026-86950 to Apple. Neither company has disclosed technical details about how the flaw was discovered or the specific attacks in which it was used.




