top of page

Apple releases emergency patch for actively exploited CoreGraphics zero-day vulnerability

4 days ago
3 min read

Apple has released new operating system updates to address a severe information security incident. This marks the seventh zero-day vulnerability that the tech giant has had to address since the beginning of the year, following signs of exploitation in attack campaigns targeting highly selected individuals.

apple-zero-day vulnerability
Apple patched the zero-day vulnerability

Details on Apple's zero-day vulnerability and affected devices

The new security issue is designated as CVE-2026-86950, scoring a risk rating of 8.8 on the Common Vulnerability Scoring System (CVSS). This flaw resides in CoreGraphics – a framework used by Apple across all its operating systems to process and render 2D graphical images.

Technically, the issue stems from an out-of-bounds write error. When a device processes a maliciously crafted file, threat actors can exploit this weakness to execute arbitrary code on the victim's device. Apple addressed the issue by improving memory bounds checking to prevent unauthorized data writes.

The fix is currently available in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe, and macOS Sequoia. Affected devices include iPhone 11 and later models, multiple iPad generations (11-inch iPad Pro 1st generation and later, 12.9-inch iPad Pro 3rd generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, iPad mini 5th generation and later), and Mac computers. Apple confirmed that the observed attacks targeted devices running iOS versions prior to iOS 27.

Level of sophistication and emergency mitigation directive

The CVE-2026-86950 vulnerability was discovered and reported by the Meta Product Security team. In its advisory, Apple issued a warning that the flaw may have been exploited in an "extremely sophisticated" attack campaign targeting specific individuals. However, the company did not disclose details regarding the identities of the victims, the number of affected devices, or the group behind the attack.

Apple's wording suggests that this is not a widespread malware distribution campaign, but rather one likely tied to targeted spyware operations.

Given the high risk, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-86950 to its Known Exploited Vulnerabilities (KEV) catalog. Under Binding Operational Directive (BOD) 26-04, U.S. federal civilian agencies are required to complete patch deployment within three days, as well as conduct forensic reviews of their systems by October 2 to check for potential compromises via this vulnerability.

Analysis and advice from security experts

Adam Boynton, enterprise security manager at Jamf, noted that the appearance of a vulnerability in CoreGraphics – a system-wide content processing component – reflects an ongoing trend of attackers constantly seeking entry vectors through input data. Although current attacks only target a small group of users, this remains an indicator of escalating threats directed at core system components.

Ensar Seker, Chief Information Security Officer (CISO) at SOCRadar, evaluated that a memory corruption flaw arising during file processing can pave the way for low-interaction or "zero-click" attacks – where victims become infected without needing to click on suspicious links. In practice, attackers often chain multiple vulnerabilities together: using one flaw for initial code execution, another to bypass security sandboxes or escalate privileges, ultimately leading to sensitive data exfiltration.

Because many high-profile individuals possessing critical information use Apple devices, experts advise organizations to proactively shorten software patching cycles, implement centralized device management, and treat these updates as emergency procedures rather than waiting for routine maintenance windows. Upgrading operating systems to the latest versions immediately is an essential measure to secure devices and data.

follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
bottom of page