
Apple is urging users to update after patching a CoreGraphics vulnerability that attackers have already exploited against specific individuals. The flaw could let malicious files run code on vulnerable iPhones, iPads and Macs.
Apple has released security updates for iPhones, iPads and Macs to address a dangerous vulnerability that attackers appear to have discovered before a patch was available.
The vulnerability, tracked as CVE-2026-86950, affects CoreGraphics, an Apple framework responsible for drawing and processing graphics across its operating systems.
Processing a specially crafted file on a vulnerable device could lead to arbitrary code execution – potentially allowing malicious code to run on the device, Apple said in its security advisory.
This isn't merely a theoretical threat.
“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27,” the company says.
CVE-2026-86950 is an out-of-bounds write vulnerability, a type of memory-safety flaw that can allow software to write data outside the area of memory allocated to it.
Depending on the circumstances, bugs of this kind can cause crashes or memory corruption and, more seriously, give attackers a way to execute their own code.
Apple says it fixed the problem through improved bounds checking. The vulnerability was reported by Meta Product Security.
Apple has provided very few details about the attacks themselves. They haven’t said who was targeted, how attackers delivered the malicious content, how many people were affected or what happened after the vulnerability was exploited.
The wording of Apple's advisory is nevertheless significant. The company says the flaw was used in an “extremely sophisticated” attack against “specific targeted individuals,” suggesting a focused operation rather than widespread attacks against ordinary Apple users.
The Cupertino tech titan typically reserves this kind of wording for what often turns out to be a targeted spyware campaign.
However, the company has not said spyware was involved, and there is currently no public evidence identifying the attackers or the tools they used.
The vulnerability arrives only weeks after Apple patched another potentially dangerous flaw in its image-processing technology.
That earlier vulnerability, CVE-2026-65346, affected Apple's ImageIO framework and could also lead to arbitrary code execution when a device processed maliciously crafted content.
Unlike the newly disclosed CoreGraphics vulnerability, Apple did not report CVE-2026-65346 as being exploited in the wild.
Sophisticated attackers are particularly interested in vulnerabilities in components that process images, documents and other incoming content are particularly interesting because they may handle data automatically or with very little interaction from the user.
Past mercenary spyware operations have demonstrated just how dangerous such attack chains can be. Some have used so-called zero-click exploits, where receiving specially crafted content is enough to trigger part of an attack without the victim knowingly opening a malicious attachment or clicking a suspicious link.
There is no indication from Apple that CVE-2026-86950 itself is a zero-click vulnerability. But its exploitation in a sophisticated targeted attack makes installing the patch particularly important.
Apple patched the flaw on Sept. 28 in iOS 26.7.1 and iPadOS 26.7.1. The updates are available for iPhone 11 and later, along with supported iPad Pro, iPad Air, iPad and iPad mini models.
The same CoreGraphics vulnerability was also patched in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
Apple's advisory specifically refers to attacks against devices running versions of iOS before iOS 27. The company has not said which exact versions were compromised.
Apple currently lists iOS and iPadOS 27.0.1 and macOS 27.0.1 as its latest operating-system releases for compatible hardware.
The immediate advice is simple: update your devices.
On an iPhone or iPad, go to Settings > General > Software Update and install the newest version offered for your device.
On a Mac, open System Settings > General > Software Update and check for available updates.
It's also worth taking a few additional precautions:
Apple's description suggests CVE-2026-86950 has so far been used selectively rather than in a broad campaign.
That should provide some perspective for the average iPhone or Mac owner. There is no evidence that millions of Apple users are suddenly being attacked through malicious files.
But a zero-day becomes a different security problem once it is disclosed and patched. Attackers can study updates, understand what Apple changed and even try to reproduce the vulnerability against devices that remain unpatched.
The fact that CVE-2026-86950 was apparently valuable enough to be used in a sophisticated targeted operation is reason enough not to leave that window open.
Bottom line: Apple has already seen signs that attackers exploited this flaw before a fix was available. The patch is available now. Install it.
On topic:
Update your iPhone and Mac! Apple patches image flaw with spyware potential
WhatsApp detects new spyware activity from Israel’s NSO Group despite court order
tags
Filip has 17 years of experience in technology journalism. In recent years, he has focused on cybersecurity in his role as a Security Analyst at Bitdefender.
View all posts