Back Cyberkendra Apple Patches CoreGraphics Zero-Day CVE-2026
Apple confirmed targeted exploitation on pre-iOS 27 devices, and SlowMist says the fix likely closes a hole used against crypto wallet users.
Vivek is a staff writer and technology contributor at Cyber Kendra, covering the latest tech news, cybersecurity, and digital insights.
Apple on Monday released iOS 26.7.1 and iPadOS 26.7.1 to patch a CoreGraphics zero-day that may have been exploited in targeted attacks against iPhone users.
The vulnerability is tracked as CVE-2026-86950 and has a CVSS score of 8.8. It is an out-of-bounds write in CoreGraphics, the framework Apple’s operating systems use to render and manipulate 2D graphics. According to Apple, processing a maliciously crafted file can lead to arbitrary code execution.
Apple said it is aware of a report that the flaw may have been exploited in an “extremely sophisticated attack” targeting specific individuals running earlier versions of iOS. The company credited Meta Product Security with reporting the bug. It did not name the attackers or the targets, nor did it say how many devices were compromised.
An out-of-bounds write occurs when software stores data beyond the edge of the memory region allocated for it. An attacker who controls that overflowing data can corrupt neighboring memory and redirect the program. A booby-trapped file then runs attacker code as soon as CoreGraphics parses it. Apple fixed the issue with improved bounds checking.
Apple has not explained how the malicious file reached its victims. Ensar Seker, CISO at SOCRadar, told Dark Reading that a memory-corruption bug of this kind can enable a low-interaction or even zero-click attack chain when paired with a suitable delivery mechanism.
On Tuesday, blockchain security firm SlowMist said Apple’s update is “highly relevant” to iOS exploitation activity it has tracked targeting sensitive crypto wallet data. SlowMist CISO 23pds went further in a separate post . He tied the patch to a zero-day he said was used in attacks involving crypto wallets.
Apple’s advisory does not mention cryptocurrency, and neither company has published evidence linking CVE-2026-86950 to a specific theft. Cyber Kendra has not independently verified the connection.
SlowMist’s warning follows its September 19 report of crypto assets stolen from users who had installed versions 1.1 and 1.2 of FomoPeek. A joint investigation by SlowMist and OKX found an iOS kernel exploitation framework with eight exploit methods inside those builds. SlowMist has not said the FomoPeek campaign used the CoreGraphics flaw.
The US Cybersecurity and Infrastructure Security Agency added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog on Tuesday, citing evidence of active exploitation.
The iOS and iPadOS fix covers:
iPad Pro 12.9-inch (third generation and later)
iPad Pro 11-inch (first generation and later)
iPad Air (third generation and later)
iPad (eighth generation and later)
iPad mini (fifth generation and later)
Apple shipped the same patch in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 shipped without any published CVE entries. Reports say that the current generation does not appear to be affected.
Users who remain on iOS 26 should install 26.7.1 or move to iOS 27. SlowMist also advised crypto holders to avoid apps from untrusted sources and to be wary of unexpected files and links opened in Safari or in-app browsers.
Join the conversation. Ask questions, solutions, and help others.
Be the first to start the discussion!
Google PageBreak AI Agent Finds 500+ XSS Flaws
WhatsApp Malware Targets Malaysia via KuGou-Signed File
Microsoft Details NeedyMantis Post-Compromise Malware
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
