Particle.news

Apple Patches CoreGraphics Zero-Day That May Have Been Used in Targeted Attacks

A CISA remediation order for federal agencies makes immediate updating urgent.

Overview

  • Apple released fixes for CVE-2026-86950 in iOS and iPadOS 26.7.1 and macOS Tahoe and Sequoia updates to stop an out-of-bounds write in CoreGraphics that can allow arbitrary code execution when a device processes a malicious file.
  • Apple credited Meta Product Security with reporting the bug and said it is aware of a report that the flaw "may have been exploited in an extremely sophisticated attack" against specific individuals.
  • The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to apply the patch by October 2, 2026.
  • Researchers from Calif published a public proof-of-concept that embeds a crafted TrueType font in a PDF to trigger a crash on unpatched devices, noting the PoC demonstrates memory corruption rather than a complete remote-code-execution chain.
  • The fix matters because CoreGraphics parses common content such as images and PDFs, which can enable low- or zero-interaction attacks; historically similar Apple fixes have been linked to targeted spyware campaigns, so high-value and crypto users are urged to update and review devices for signs of compromise.