Apple patches zero-day behind ‘extremely sophisticated’ iPhone attacks

Filip TRUȚĂ

October 01, 2026

Apple patches zero-day behind ‘extremely sophisticated’ iPhone attacks

Apple is urging users to update after patching a CoreGraphics vulnerability that attackers have already exploited against specific individuals. The flaw could let malicious files run code on vulnerable iPhones, iPads and Macs.

Key takeaways

  • Apple has patched a CoreGraphics zero-day tracked as CVE-2026-86950
  • Processing a maliciously crafted file could let attackers execute code on a vulnerable device
  • Apple says the vulnerability may have been exploited in an “extremely sophisticated attack” against specific targeted individuals
  • The company has not said who was targeted, how the attacks worked or whether spyware was involved
  • The vulnerability affects older iOS, iPadOS and macOS releases and was reported by Meta Product Security
  • Apple users should install the latest operating system available for their device as soon as possible

Apple has released security updates for iPhones, iPads and Macs to address a dangerous vulnerability that attackers appear to have discovered before a patch was available.

The vulnerability, tracked as CVE-2026-86950, affects CoreGraphics, an Apple framework responsible for drawing and processing graphics across its operating systems.

Processing a specially crafted file on a vulnerable device could lead to arbitrary code execution – potentially allowing malicious code to run on the device, Apple said in its security advisory.

This isn't merely a theoretical threat.

“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27,” the company says.

What happened?

CVE-2026-86950 is an out-of-bounds write vulnerability, a type of memory-safety flaw that can allow software to write data outside the area of memory allocated to it.

Depending on the circumstances, bugs of this kind can cause crashes or memory corruption and, more seriously, give attackers a way to execute their own code.

Apple says it fixed the problem through improved bounds checking. The vulnerability was reported by Meta Product Security.

Apple has provided very few details about the attacks themselves. They haven’t said who was targeted, how attackers delivered the malicious content, how many people were affected or what happened after the vulnerability was exploited.

The wording of Apple's advisory is nevertheless significant. The company says the flaw was used in an “extremely sophisticated” attack against “specific targeted individuals,” suggesting a focused operation rather than widespread attacks against ordinary Apple users.

The Cupertino tech titan typically reserves this kind of wording for what often turns out to be a targeted spyware campaign.

However, the company has not said spyware was involved, and there is currently no public evidence identifying the attackers or the tools they used.

Another dangerous flaw in how devices process files

The vulnerability arrives only weeks after Apple patched another potentially dangerous flaw in its image-processing technology.

That earlier vulnerability, CVE-2026-65346, affected Apple's ImageIO framework and could also lead to arbitrary code execution when a device processed maliciously crafted content.

Unlike the newly disclosed CoreGraphics vulnerability, Apple did not report CVE-2026-65346 as being exploited in the wild.

Image-processing flaws are extremely valuable to hackers

Sophisticated attackers are particularly interested in vulnerabilities in components that process images, documents and other incoming content are particularly interesting because they may handle data automatically or with very little interaction from the user.

Past mercenary spyware operations have demonstrated just how dangerous such attack chains can be. Some have used so-called zero-click exploits, where receiving specially crafted content is enough to trigger part of an attack without the victim knowingly opening a malicious attachment or clicking a suspicious link.

There is no indication from Apple that CVE-2026-86950 itself is a zero-click vulnerability. But its exploitation in a sophisticated targeted attack makes installing the patch particularly important.

Which devices received the fix?

Apple patched the flaw on Sept. 28 in iOS 26.7.1 and iPadOS 26.7.1. The updates are available for iPhone 11 and later, along with supported iPad Pro, iPad Air, iPad and iPad mini models.

The same CoreGraphics vulnerability was also patched in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.

Apple's advisory specifically refers to attacks against devices running versions of iOS before iOS 27. The company has not said which exact versions were compromised.

Apple currently lists iOS and iPadOS 27.0.1 and macOS 27.0.1 as its latest operating-system releases for compatible hardware.

What Apple users should do

The immediate advice is simple: update your devices.

On an iPhone or iPad, go to Settings > General > Software Update and install the newest version offered for your device.

On a Mac, open System Settings > General > Software Update and check for available updates.

It's also worth taking a few additional precautions:

  • Enable automatic updates. Security patches are particularly important when a vulnerability is already being exploited
  • Don't rely entirely on spotting suspicious files. Sophisticated exploits may not look obviously malicious, and some attacks require little or no meaningful interaction from the victim
  • Keep browsers and messaging apps updated too. Attack chains frequently combine multiple vulnerabilities or delivery mechanisms
  • Be cautious with unexpected links and attachments. Not every advanced attack is zero-click; phishing and social engineering remain effective ways of getting malicious content onto a device
  • Use independent security software to help detect malicious links, downloads and other threats that may accompany an attack
  • Consider Lockdown Mode if you face elevated risk. Journalists, activists, executives, government officials and others who believe they may be targeted by sophisticated mercenary spyware can use Apple's hardened security mode to reduce the device's attack surface

Most people aren't the target – but they should still update

Apple's description suggests CVE-2026-86950 has so far been used selectively rather than in a broad campaign.

That should provide some perspective for the average iPhone or Mac owner. There is no evidence that millions of Apple users are suddenly being attacked through malicious files.

But a zero-day becomes a different security problem once it is disclosed and patched. Attackers can study updates, understand what Apple changed and even try to reproduce the vulnerability against devices that remain unpatched.

The fact that CVE-2026-86950 was apparently valuable enough to be used in a sophisticated targeted operation is reason enough not to leave that window open.

Bottom line: Apple has already seen signs that attackers exploited this flaw before a fix was available. The patch is available now. Install it.

On topic:

Update your iPhone and Mac! Apple patches image flaw with spyware potential

WhatsApp detects new spyware activity from Israel’s NSO Group despite court order

macOS ‘Screen Sharing’ flaw exploited for crypto-mining

tags


Author


Filip TRUȚĂ

Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.

View all posts

You might also like

Bookmarks


loader