Particle.news

Apple Patches CoreGraphics Zero‑Day That May Have Been Used in Targeted Attacks

Apple says the bug could have powered extremely sophisticated attacks and urged users to install emergency fixes to reduce ongoing risk.

Overview

  • Apple released emergency updates Monday that fix CVE-2026-86950 in iOS/iPadOS 26.7.1 and macOS Tahoe/Sequoia 26.7.1 and 15.8.1 to stop an out-of-bounds write in CoreGraphics.
  • The company credited Meta Product Security with reporting the flaw and said it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific iOS users while providing no public details about victims or delivery methods.
  • CoreGraphics is the system graphics and PDF renderer, and the out-of-bounds write could allow arbitrary code execution when processing a maliciously crafted file, so plausible delivery paths include images or PDFs delivered by web pages, email, or messaging apps.
  • Security vendors have urged users on affected OS branches to update immediately and told high-value targets and cryptocurrency holders to harden devices and assume risk because installing the patch does not undo prior data theft.
  • Authorities and technical attribution remain limited for now, with iOS/macOS 27 releases appearing unaffected and CISA not yet listing the CVE in its Known Exploited Vulnerabilities catalog, so further investigation and vendor notices are likely to follow.