« All news

AlertHigh· Updated on

Apple patches a CoreGraphics flaw exploited in targeted attacks against iPhone, iPad and Mac

CVE-2026-86950 allows arbitrary code execution when a maliciously crafted file is processed. Apple acknowledges it may have been used in an extremely sophisticated attack against specific individuals, and CISA has added it to its known exploited vulnerabilities catalogue.

What happened

On 28 September 2026 Apple released security updates fixing CVE-2026-86950, an out-of-bounds write flaw in CoreGraphics, the component that handles image and graphics processing. According to Apple's advisory, simply processing a maliciously crafted file may lead to arbitrary code execution on the device.

Apple states that it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals, on versions of iOS before iOS 27. The company addressed it with improved bounds checking. The discovery is credited to Meta Product Security.

The vulnerability carries a CVSS score of 8.8 (high), with a network attack vector and user interaction required: the victim only needs to open or process a file prepared by the attacker.

Exploitation status

CISA added CVE-2026-86950 to its KEV catalogue on 29 September 2026, confirming active exploitation, and set 2 October 2026 as the remediation deadline for US federal agencies. There is no information on whether it has been used in ransomware campaigns.

FIRST's EPSS score is 0.8 %, a low probability of widespread exploitation over the next 30 days. That figure does not reduce the seriousness of the case: this is a highly crafted, selective attack of the kind associated with espionage campaigns against specific individuals, rather than indiscriminate exploitation.

Who is affected

According to Apple's advisory and NVD data, the following systems are affected, with fixes available in these versions:

What to do

Given the confirmed exploitation, the recommendation is to update urgently. Concrete steps:

Sources

Affected technologies

Apple iOSApple iPadOSApple macOSApple iPhoneApple iPad

Vulnerabilities (1)

CVESeverityActive exploitationPublishedNVD status
CVE-2026-86950High (8.8)⚠ Active exploitation9/28/2026Analyzed

Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.