AI News Feed
Market watch
Cybersecurity

Apple patches CoreGraphics zero-day CVE-2026-86950 used in targeted attacks

Apple has released fixes for CVE-2026-86950, a high-severity CoreGraphics zero-day in iOS, iPadOS and macOS that may have been exploited in extremely sophisticated attacks against specific targeted individuals. Users are urged to update promptly.

The vulnerability is tracked as CVE-2026-86950 and has a severity score of 8.8 out of 10, or high. The National Vulnerability Database describes it as an out-of-bounds issue that allows threat actors to execute arbitrary code through a maliciously crafted file. The bug can also be exploited to crash programs and corrupt data. Apple said it fixed the issue with improved bounds checking. CoreGraphics is Apple's low-level 2D graphics framework used across iOS, iPadOS, macOS and other platforms, where it helps developers draw and render visual elements such as lines, shapes, images and text, and handles colors, transparency, gradients and clipping.

According to TechRadar, the devices covered by the advisory include iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, iPad mini 5th generation and later, and Mac devices running macOS Sequoia 15.8.1 and Tahoe 26.7.1.

Apple said it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. The company did not identify the report or the victims. TechRadar reported that the bug was flagged by Meta Product Security, and that it could not find anyone discussing the report. Apple is known for withholding details of vulnerabilities until it is confident that a significant majority of affected devices have been patched. The wording about extremely sophisticated attacks against specific targeted individuals is also wording Apple usually uses for state-sponsored espionage attacks against diplomats and politicians, high-value targets such as tech CEOs, journalists, political opponents and dissidents. Although it is not mentioned in the report, tech companies like Apple and Google tend to notify victims when they are targeted in such attacks.

The last time Apple used similar wording was in February 2026, when it patched CVE-2026-20700. In that incident it also did not discuss the attackers or the victims, but the flaw was discovered by Google's Threat Analysis Group, a department assigned with investigating primarily state-sponsored hacking campaigns. CVE-2026-86950 is now the second zero-day vulnerability Apple has patched this year. Last year, Apple addressed seven zero-day vulnerabilities exploited in the wild: CVE-2025-24085, CVE-2025-24200, CVE-2025-24201, CVE-2025-31200, CVE-2025-31201, CVE-2025-43529 and CVE-2025-14174.

Users are advised to apply the patches without delay. Apple users with automatic updates enabled should receive the security fix automatically, but those who have not yet updated should manually check Settings → General → Software Update and install iOS or iPadOS 26.7.1. TechRadar noted that the update is particularly important for high-value targets such as diplomats, dissidents, whistleblowers, political opposition and journalists.

Editor's Summary

Apple has released fixes for CVE-2026-86950, a high-severity CoreGraphics zero-day affecting iOS, iPadOS and macOS. Apple said the flaw may have been exploited in extremely sophisticated targeted attacks, and users are urged to update promptly. It is the second zero-day Apple has patched this year.