Apple Patches CoreGraphics Zero-Day Exploited in Attacks
Apple has rolled out emergency security updates to address a critical zero-day vulnerability affecting CoreGraphics, which has been actively exploited in targeted attacks.

CoreGraphics Vulnerability Overview
Apple has released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. Tracked as CVE-2026-86950, this flaw stems from an out-of-bounds write weakness discovered by Meta Product Security in CoreGraphics, a framework used for two-dimensional vector graphics, image rendering, and text drawing across iOS, macOS, iPadOS, watchOS, and tvOS.
Successful exploitation of out-of-bounds write vulnerabilities can let attackers crash a program, corrupt data, or, in the worst case, gain remote code execution by writing data outside the allocated memory buffer. Processing a maliciously crafted file may lead to arbitrary code execution, which Apple addressed through improved bounds checking.
Targeted Attacks and Advisory Details
Apple noted that it is aware of a report indicating this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, as it warned on Monday. While both iOS and macOS are impacted by the underlying component flaw, Apple's advisory suggests that attacks have only been observed against the former.
Because CoreGraphics handles 2D graphics and PDF rendering across operating systems, malicious files could theoretically arrive via web pages, email attachments, or messaging apps. In some scenarios, automatic attachment and link previews could potentially facilitate zero-click exploitation, though Apple has not explicitly detailed the precise delivery mechanism used in these specific targeted incidents.

Affected Devices and Software Updates
The list of impacted devices is extensive, covering a wide array of older and newer hardware models. Affected hardware includes iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later, alongside Macs running applicable macOS software.
To mitigate these risks, users are urged to apply the latest platform updates immediately. Apple has addressed the issue in iOS 26.7.1 and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. The latest versions, such as iOS 27 and macOS Golden Gate 27, do not appear to be affected by this specific security issue.
Meta's Involvement and Prior Fixes
Meta's product security team reported the vulnerability to Apple. In response to inquiries, Meta stated that as part of its routine security work, it regularly reports vulnerabilities found in third-party software to other vendors so they can be patched. The company did not provide further information on the specific attacks exploiting CVE-2026-86950 or comment on whether messaging applications were involved.
With this vulnerability, Apple has fixed two zero-day flaws exploited in the wild since the start of the year. The other issue, an arbitrary code execution vulnerability in dyld tracked as CVE-2026-20700, was patched in February after also being exploited in extremely sophisticated targeted attacks. Security experts continue to advise prompt updates across all compatible devices to prevent ongoing exploitation.
Sources
- BleepingComputerApple patches CoreGraphics zero-day flaw exploited in attacks
- SecurityWeekApple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’