Particle.news

Apple Patches CoreGraphics Zero-Day That May Have Targeted Specific iOS Users

The update fixes an out‑of‑bounds write that can let crafted images or PDFs run attacker code and raises urgency for users on older OS branches to install patches.

Overview

  • Apple released security updates for iOS and iPadOS 26.7.1 and for macOS Tahoe 26.7.1 and Sequoia 15.8.1 to fix CVE-2026-86950 in the CoreGraphics framework.
  • Apple credited Meta Product Security with reporting the bug and said it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific individuals, while providing no details on victims or delivery methods.
  • The flaw is an out‑of‑bounds write in CoreGraphics that can lead to arbitrary code execution when the system processes a maliciously crafted image or PDF, making web pages, email attachments, and messaging previews plausible delivery paths.
  • Security firms including SlowMist urged affected users to update quickly because device compromise can expose sensitive data such as private keys for crypto wallets, though no public proof links this CVE to confirmed wallet thefts.
  • Authorities and defenders should watch for further disclosures and for a possible CISA KEV listing that would guide enterprise and government patch priorities, and all users on iOS 26 or supported macOS branches should install the available updates now.