Apple Closes CoreGraphics Memory Flaw Linked to Precision iPhone Attacks

Apple patched CVE-2026-86950, a CoreGraphics out-of-bounds flaw enabling code execution in targeted iPhone attacks. Update iOS 26.7.1 and macOS now.

Apple Closes CoreGraphics Memory Flaw Linked to Precision iPhone Attacks
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 9 min

Apple has patched a CoreGraphics memory-safety vulnerability that may have been used against selected individuals in highly sophisticated attacks. The flaw, CVE-2026-86950, can allow arbitrary code execution when a device processes a maliciously crafted file.

Apple said the reported exploitation involved devices running iOS versions earlier than iOS 27. It has not disclosed how many people were targeted, whether the attempted compromises succeeded, or when the activity began.

The exact release date of the security updates is not known. Meta Product Security discovered and reported the vulnerability.

A crafted file can write beyond allocated memory

CVE-2026-86950 is an out-of-bounds write in CoreGraphics, the Apple framework responsible for rendering and processing graphical content.

An out-of-bounds write occurs when software places data outside the memory region allocated for an operation. Depending on the surrounding memory layout and an attacker’s control over the written data, this corruption can crash the affected process or alter execution flow.

For this vulnerability, Apple says processing a maliciously constructed file may lead to arbitrary code execution. The company corrected the underlying defect by adding improved bounds checking, which should prevent CoreGraphics from writing past the expected memory boundary.

The vulnerability carries a CVSS 3.1 score of 8.8 and the vector:

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

That vector describes a network-reachable attack requiring low complexity, no existing privileges and user interaction. Successful exploitation could have a high impact on confidentiality, integrity and availability. The exact action required from a target, the relevant file formats and the application paths capable of reaching the vulnerable CoreGraphics code have not been disclosed.

No exploit code, forensic indicators or technical account of the reported attacks is publicly identified. Apple has also not said whether CVE-2026-86950 formed part of a longer exploit chain, such as a sequence combining code execution with a sandbox escape or privilege-escalation vulnerability.

Updates cover current iPhones, iPads and two macOS branches

Apple has issued fixes for three operating-system lines:

  • iOS 26.7.1 and iPadOS 26.7.1
    • iPhone 11 and later
    • iPad Pro 12.9-inch, third generation and later
    • iPad Pro 11-inch, first generation and later
    • iPad Air, third generation and later
    • iPad, eighth generation and later
    • iPad mini, fifth generation and later
  • macOS Tahoe 26.7.1
    • Macs running macOS Tahoe
  • macOS Sequoia 15.8.1
    • Macs running macOS Sequoia

Apple has not provided a separate affected-version table defining every vulnerable build. Its exploitation statement specifically refers to targeted individuals using iOS versions before iOS 27, but the company also released fixes for iPadOS and macOS.

That distinction matters. The reported attack activity concerns older iOS releases, while the broader patch coverage indicates that vulnerable CoreGraphics code exists across multiple Apple platforms. It does not establish that exploitation occurred on iPads or Macs.

Targeted users face the highest immediate risk

Apple’s wording points to a focused operation rather than indiscriminate exploitation. Describing an attack as highly sophisticated and directed at specific individuals is consistent with carefully selected targets, although Apple has not attributed the activity to any operator or named the affected group.

The absence of a public exploit does not reduce the need to patch. Once a vulnerability is documented and corrected, attackers can compare patched and unpatched components to identify the relevant code changes. That process can accelerate independent exploit development.

Users should install the applicable update through the normal operating-system update mechanism. Organizations managing Apple fleets should verify the resulting version rather than relying solely on whether an update command was issued.

There is no disclosed workaround for systems that cannot be upgraded. No indicators of compromise, malicious filenames, hashes, domains or process patterns have been published, leaving defenders without vulnerability-specific artifacts to search for.

For potentially exposed high-risk users, ordinary endpoint review may also be insufficient. The available information does not identify where exploitation evidence would appear or whether a successful attack would leave durable traces.

CVE-2026-86950 is not reported in CISA’s KEV catalog

As of September 28, 2026, CVE-2026-86950 has no reported entry in the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog. Consequently, there is no KEV remediation deadline associated with this flaw.

That status should not be confused with Apple’s own statement. The company says it knows of a report that the vulnerability may have been exploited, but CISA has not listed it under the KEV program in the available data.

A KEV listing is operationally significant for US federal civilian agencies because it creates a binding remediation timetable under CISA directives. Its absence does not mean exploitation did not occur, particularly when a vendor has already acknowledged a report involving targeted attacks.

An earlier Apple memory flaw reached the KEV catalog

The case follows another Apple memory-corruption vulnerability associated with sophisticated targeting. CVE-2026-20700 affects dyld, Apple’s dynamic linker, and may permit an attacker who already has memory-write capability to execute arbitrary code.

CVE-2026-20700 has a CVSS 3.1 score of 7.8 and the vector:

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

NVD classifies it as CWE-119 and lists these affected version ranges:

  • Apple iPadOS before 26.3
  • iPhone OS before 26.3
  • macOS before 26.3
  • tvOS before 26.3
  • visionOS before 26.3
  • watchOS before 26.3

Apple fixed that vulnerability in iOS and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3 and watchOS 26.3. The exact date of that earlier update is not known.

CISA added CVE-2026-20700 to the KEV catalog on 2026-02-12 and set a remediation deadline of 2026-03-05 for US federal agencies. CISA required agencies to apply vendor mitigations, follow applicable BOD 22-01 guidance for cloud services, or discontinue the product when mitigations were unavailable.

Two other Apple vulnerabilities were issued in connection with the same reported campaign: CVE-2025-14174 and CVE-2025-43529. Both have CVSS scores of 8.8 and the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.

CVE-2025-14174 entered KEV on 2025-12-12, with a federal remediation deadline of 2026-01-02. CVE-2025-43529 followed on 2025-12-15, with a deadline of 2026-01-05. For both, CISA prescribed vendor mitigations, applicable BOD 22-01 measures for cloud services, or discontinuation when no mitigation was available.

CVE-2026-86950 therefore arrives against an established pattern: Apple memory-safety defects have been connected to advanced targeting, and several related vulnerabilities have subsequently triggered mandatory federal remediation. For the newest CoreGraphics flaw, installing the available updates remains the only disclosed defensive action.

Security dossiers

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →