Back Cyberinsider Apple patches CoreGraphics flaw linked to targeted iPhone attacks
Apple has released security updates for iPhones, iPads, and Macs to fix a CoreGraphics vulnerability that may have been exploited in a highly targeted attack.
The flaw, tracked as CVE-2026-86950, could allow arbitrary code execution when a device processes a maliciously crafted file.
In its security advisory , Apple said it was aware of a report that the issue may have been exploited in what it described as an “extremely sophisticated attack” against specific individuals using versions of iOS before iOS 27. Meta Product Security was credited with reporting the vulnerability.
CVE-2026-86950 is an out-of-bounds write in CoreGraphics, a framework used to draw and process graphics across Apple’s operating systems. Apple addressed the flaw with improved bounds checking but did not specify what type of file could trigger it or how the file was delivered to the targets.
The company has also not identified the people targeted, disclosed when the attacks occurred, or confirmed whether they succeeded. Although Apple issued patches for iPadOS and macOS, its exploitation warning refers specifically to earlier versions of iOS. There is no public indication in the advisories that the flaw was exploited against iPads or Macs.
The fix is available in iOS 26.7.1 and iPadOS 26.7.1 for iPhone 11 and later and supported iPad models. Apple also patched the issue in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
Earlier this year, Apple patched another flaw associated with an “extremely sophisticated attack” against targeted iPhone users. That vulnerability, CVE-2026-20700, affected the dyld dynamic linker and was reported by Google’s Threat Analysis Group. Apple linked it to a report concerning devices running iOS versions before iOS 26. The newly disclosed CoreGraphics case concerns a different component and a report involving versions before iOS 27; Apple has not connected the two investigations.
Users can check for the latest release on iPhone and iPad under Settings > General > Software Update, or on Mac under System Settings > General > Software Update.
Proton finds Russian and Chinese trackers in popular Android games
OpenAI pauses work on top AI models after agent bypasses internet restrictions
Hackers can hijack QR code domains to redirect users to phishing sites
31 Chrome VPN extensions let operators change where users’ traffic goes
Google warns ShinyHunters is mass-exploiting Oracle PeopleSoft flaw
Malicious Twitch chat messages can trigger code execution on OBS Studio
Bill specializes in explaining complex technical topics to a non-technical audience. In his 30+ year career, he has covered many of the technological advances that shape our lives. Today, Bill uses those skills to help people protect their privacy and security against the ever-growing assaults on both.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
