Apple has released patches for a serious vulnerability in its CoreGraphics library—tracked as CVE-2026-86950—that has reportedly been used in targeted attacks. The flaw involves an “out-of-bounds write” in CoreGraphics, enabling arbitrary code execution when specially crafted malicious files are processed. A security researcher at Meta first flagged the issue, prompting the rapid fix.
The flaw affected older versions of iOS, iPadOS, and macOS. Attackers could exploit the bug by getting the system to process a maliciously designed graphics file, potentially enabling them to run code of their choosing without authorization. Apple has updated CoreGraphics to include better bounds checking to prevent such memory‐based overflows.
Affected Platforms and Patch Details
The vulnerability is patched in:
- iOS 26.7.1 and iPadOS 26.7.1 — covers iPhone 11 onwards, iPad Pro (3rd Gen 12.9-inch and later), iPad Pro 11-inch 1st Gen and later, iPad Air 3rd Gen, iPad 8th Gen, and iPad mini 5th Gen.
- macOS Tahoe 26.7.1.
- macOS Sequoia 15.8.1.
Apple said it’s aware this vulnerability may have been used in a “highly sophisticated” campaign targeting specific individuals running iOS versions before iOS 27. The company did not provide details on how many people were affected, how many successful intrusions occurred, or when the first exploit took place.
This isn’t the first time Apple has responded to such kernel‐level threats. Earlier in 2026, a separate memory corruption issue in its dynamic loader (dyld) — CVE-2026-20700 — was also addressed after similar reports of weaponization in focused attacks.
What Users Should Do
If you’re using any of the affected devices or operating systems, update immediately to the versions listed above. Apple’s system updates include the necessary fixes. For devices that can’t upgrade, minimize exposure to untrusted file sources or triggering content (e.g. avoid opening files or images from unknown senders). Enterprises should deploy the patch across all managed devices as promptly as possible.
The discovery of this vulnerability by Meta Product Security underscores the importance of external reporting in security. As attackers increasingly use zero-days in targeted attacks, proactive collaboration between private researchers and platform vendors becomes critical.
Analysis: This patch underlines the growing trend of zero-day threats being used not in mass campaigns, but in surgical attacks against high-value targets. The lack of detail around the exploit’s scope suggests Apple is still gathering intelligence. What’s clear is that threats are creeping in deeper: CoreGraphics isn’t a deeply privileged driver or kernel module, yet flaws here still enable serious compromise. Going forward, expect more attention and pressure on Apple’s graphics and image handling code, areas that have long been low-visibility but high-risk. Security teams should not just patch swiftly but audit parsers, codecs, and rendering libraries as part of threat-driven defense strategies.