
Apple has released security updates for iPhones, iPads, and Macs to fix a CoreGraphics vulnerability that may have been exploited in a highly targeted attack.
The flaw, tracked as CVE-2026-86950, could allow arbitrary code execution when a device processes a maliciously crafted file.
In its security advisory, Apple said it was aware of a report that the issue may have been exploited in what it described as an “extremely sophisticated attack” against specific individuals using versions of iOS before iOS 27. Meta Product Security was credited with reporting the vulnerability.
CVE-2026-86950 is an out-of-bounds write in CoreGraphics, a framework used to draw and process graphics across Apple’s operating systems. Apple addressed the flaw with improved bounds checking but did not specify what type of file could trigger it or how the file was delivered to the targets.
The company has also not identified the people targeted, disclosed when the attacks occurred, or confirmed whether they succeeded. Although Apple issued patches for iPadOS and macOS, its exploitation warning refers specifically to earlier versions of iOS. There is no public indication in the advisories that the flaw was exploited against iPads or Macs.
The fix is available in iOS 26.7.1 and iPadOS 26.7.1 for iPhone 11 and later and supported iPad models. Apple also patched the issue in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
Earlier this year, Apple patched another flaw associated with an “extremely sophisticated attack” against targeted iPhone users. That vulnerability, CVE-2026-20700, affected the dyld dynamic linker and was reported by Google’s Threat Analysis Group. Apple linked it to a report concerning devices running iOS versions before iOS 26. The newly disclosed CoreGraphics case concerns a different component and a report involving versions before iOS 27; Apple has not connected the two investigations.
Users can check for the latest release on iPhone and iPad under Settings > General > Software Update, or on Mac under System Settings > General > Software Update.






Leave a Reply