Apple patches a CoreGraphics flaw exploited in targeted attacks against iPhone, iPad and Mac
CVE-2026-86950 allows arbitrary code execution when a maliciously crafted file is processed. Apple acknowledges it may have been used in an extremely sophisticated attack against specific individuals, and CISA has added it to its known exploited vulnerabilities catalogue.
What happened
On 28 September 2026 Apple released security updates fixing CVE-2026-86950, an out-of-bounds write flaw in CoreGraphics, the component that handles image and graphics processing. According to Apple's advisory, simply processing a maliciously crafted file may lead to arbitrary code execution on the device.
Apple states that it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals, on versions of iOS before iOS 27. The company addressed it with improved bounds checking. The discovery is credited to Meta Product Security.
The vulnerability carries a CVSS score of 8.8 (high), with a network attack vector and user interaction required: the victim only needs to open or process a file prepared by the attacker.
Exploitation status
CISA added CVE-2026-86950 to its KEV catalogue on 29 September 2026, confirming active exploitation, and set 2 October 2026 as the remediation deadline for US federal agencies. There is no information on whether it has been used in ransomware campaigns.
FIRST's EPSS score is 0.8 %, a low probability of widespread exploitation over the next 30 days. That figure does not reduce the seriousness of the case: this is a highly crafted, selective attack of the kind associated with espionage campaigns against specific individuals, rather than indiscriminate exploitation.
Who is affected
According to Apple's advisory and NVD data, the following systems are affected, with fixes available in these versions:
- iOS 26.7.1 and iPadOS 26.7.1: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later.
- macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1.
- Pay particular attention to high-risk profiles: executives, staff with access to sensitive information, journalists or activists, who are the typical targets of this kind of attack.
What to do
Given the confirmed exploitation, the recommendation is to update urgently. Concrete steps:
- Deploy iOS 26.7.1, iPadOS 26.7.1, macOS Sequoia 15.8.1 or macOS Tahoe 26.7.1 as applicable, prioritising devices belonging to executives and users with access to critical data.
- Push the update from your mobile device management (MDM) platform and review your inventory to find devices still running earlier versions.
- Remind users not to open files or images received through unverified channels until the patch has been applied.
- For high-risk profiles, consider enabling Apple's Lockdown Mode as an additional safeguard against targeted attacks.
- Review logs and unusual behaviour on devices belonging to people who may have been targeted.
Sources
Affected technologies
Vulnerabilities (1)
| CVE | Severity | Active exploitation | Published | NVD status |
|---|---|---|---|---|
| CVE-2026-86950 | High (8.8) | ⚠ Active exploitation | 9/28/2026 | Analyzed |
Written automatically from NVD, CISA KEV and vendor advisory data. Always check affected versions and patches in the vendor's official advisory before acting.