Apple Patches Actively Exploited Zero-Day in CoreGraphics
Apple issues emergency updates to fix a zero-day flaw in iOS and macOS, exploited in targeted attacks against specific individuals.
By
Content Team
ON THIS PAGE
Want more insights like this?
Subscribe to our newsletter to get the latest software protection strategies delivered to your inbox.
By submitting your email, you consent to Codekeeper contacting you and agree to our privacy policy.
Apple shipped emergency updates on September 28, 2026 to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics that lets a maliciously crafted file run arbitrary code on the device. The fixes landed in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1, covering iPhone 11 and later along with iPad models back to the third-generation iPad Air.
Apple says the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." Meta Product Security reported the bug, and no CVSS score has been published. Update through Settings > General > Software Update.
Source: Cybersecurity News
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo