Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Key Points:
- Apple has released security updates for older versions of iOS, iPadOS, and macOS to fix a vulnerability (CVE-2026-86950) in the CoreGraphics component that could allow arbitrary code execution through maliciously crafted files.
- The flaw, discovered and reported by Meta Product Security, was addressed by improving bounds checking, and Apple acknowledged it may have been exploited in targeted attacks on iOS versions prior to iOS 27.
- Apple did not disclose details on the number of targeted individuals, the success of any attacks, or the timeline of the vulnerability's exploitation.
- The security patch is available for iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1, covering a range of iPhone, iPad, and Mac devices.
- This update follows a previous fix in February for a memory corruption issue in dyld (CVE-2026-20700) that was also exploited in sophisticated cyber attacks.