Overview
- Apple released fixes in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address CVE-2026-86950.
- CVE-2026-86950 is an out-of-bounds write in the CoreGraphics framework that can allow arbitrary code execution when the system processes a specially crafted image or PDF.
- Apple said it learned of the flaw from Meta Product Security and warned the bug may have been used in extremely sophisticated, targeted attacks against iOS versions before iOS 27.
- The company did not disclose how many people were targeted, when attacks occurred, or whether any attempts succeeded, and CISA has not added the vulnerability to its Known Exploited Vulnerabilities catalog.
- CoreGraphics renders 2D graphics and PDF previews across apps, so a malicious file delivered through a web page, email or message could trigger a stealthy or zero-click compromise and users on affected devices should install the update now.