<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Apple Patches Actively Exploited Zero-Day in CoreGraphics

Apple issues emergency updates to fix a zero-day flaw in iOS and macOS, exploited in targeted attacks against specific individuals.
Content Team

Apple shipped emergency updates on September 28, 2026 to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics that lets a maliciously crafted file run arbitrary code on the device. The fixes landed in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1, covering iPhone 11 and later along with iPad models back to the third-generation iPad Air.

Apple says the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." Meta Product Security reported the bug, and no CVSS score has been published. Update through Settings > General > Software Update.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo