Apple Patches CoreGraphics Flaw Used in Targeted Attacks

Apple has patched a CoreGraphics vulnerability that attackers used against a small number of people running older Apple operating systems. The flaw could let a malicious file run code on an affected device.
Apple Patches CoreGraphics Flaw Used in Targeted Attacks
Share

Apple has released security updates for iPhone, iPad and Mac software to fix CVE-2026-86950, a CoreGraphics flaw exploited in targeted attacks against users of older operating systems. A maliciously crafted file could trigger arbitrary code execution on an affected device.

The company described the activity as an extremely sophisticated campaign aimed at a small number of individuals, as first reported by The Hacker News. Apple said the weakness was used in attacks rather than merely discovered by researchers.

The bug sits in Apple’s file-processing framework

CVE-2026-86950 is an out-of-bounds write in CoreGraphics, the Apple framework involved in processing graphics and related file content. Out-of-bounds writes occur when software writes data beyond the intended memory area, potentially allowing an attacker to alter how a program runs.

Apple addressed the issue with improved bounds checking. That change is designed to stop the framework from accepting data that would write outside the permitted memory range.

Users on older releases should install the fixes

The patch is available in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. People running those releases should install the updates promptly, particularly because exploitation has already occurred outside a laboratory setting.

  • iOS 26.7.1 fixes the issue on supported iPhones.
  • iPadOS 26.7.1 delivers the repair for supported iPads.
  • macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 include the Mac fix.

The limited scope does not remove the risk for affected people. File-processing bugs can offer a route into a device when a target receives or opens crafted content, and Apple’s acknowledgment of real-world use gives this update greater urgency than a purely theoretical defect. The affected population appears limited, yet targeted campaigns often focus on people whose devices hold sensitive communications or access to valuable accounts.

Apple has not named the attackers or the people targeted, and it has not disclosed how the malicious files reached devices, what file types they used, or when the activity began and ended. It is also unconfirmed whether platforms outside the listed affected versions were vulnerable. iOS 27.0.1, iPadOS 27.0.1 and macOS Golden Gate 27.0.1 had no published CVE entries for this flaw at the time of publication.

This article was produced with AI assistance from multi-source reporting and is published under our editorial standards.

Bose Introduces USB-C Wired Earbuds With Active Noise Cancellation

Bose Introduces USB-C Wired Earbuds With Active Noise Cancellation

Prev