Apple Closes CoreGraphics Memory Flaw Linked to Precision iPhone Attacks
Apple patched CVE-2026-86950, a CoreGraphics out-of-bounds flaw enabling code execution in targeted iPhone attacks. Update iOS 26.7.1 and macOS now.
Illustrative image generated with AI
Apple has patched a CoreGraphics memory-safety vulnerability that may have been used against selected individuals in highly sophisticated attacks. The flaw, CVE-2026-86950, can allow arbitrary code execution when a device processes a maliciously crafted file.
Apple said the reported exploitation involved devices running iOS versions earlier than iOS 27. It has not disclosed how many people were targeted, whether the attempted compromises succeeded, or when the activity began.
The exact release date of the security updates is not known. Meta Product Security discovered and reported the vulnerability.
A crafted file can write beyond allocated memory
CVE-2026-86950 is an out-of-bounds write in CoreGraphics, the Apple framework responsible for rendering and processing graphical content.
An out-of-bounds write occurs when software places data outside the memory region allocated for an operation. Depending on the surrounding memory layout and an attacker’s control over the written data, this corruption can crash the affected process or alter execution flow.
For this vulnerability, Apple says processing a maliciously constructed file may lead to arbitrary code execution. The company corrected the underlying defect by adding improved bounds checking, which should prevent CoreGraphics from writing past the expected memory boundary.
The vulnerability carries a CVSS 3.1 score of 8.8 and the vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
That vector describes a network-reachable attack requiring low complexity, no existing privileges and user interaction. Successful exploitation could have a high impact on confidentiality, integrity and availability. The exact action required from a target, the relevant file formats and the application paths capable of reaching the vulnerable CoreGraphics code have not been disclosed.
No exploit code, forensic indicators or technical account of the reported attacks is publicly identified. Apple has also not said whether CVE-2026-86950 formed part of a longer exploit chain, such as a sequence combining code execution with a sandbox escape or privilege-escalation vulnerability.
Updates cover current iPhones, iPads and two macOS branches
Apple has issued fixes for three operating-system lines:
- iOS 26.7.1 and iPadOS 26.7.1
- iPhone 11 and later
- iPad Pro 12.9-inch, third generation and later
- iPad Pro 11-inch, first generation and later
- iPad Air, third generation and later
- iPad, eighth generation and later
- iPad mini, fifth generation and later
- macOS Tahoe 26.7.1
- Macs running macOS Tahoe
- macOS Sequoia 15.8.1
- Macs running macOS Sequoia
Apple has not provided a separate affected-version table defining every vulnerable build. Its exploitation statement specifically refers to targeted individuals using iOS versions before iOS 27, but the company also released fixes for iPadOS and macOS.
That distinction matters. The reported attack activity concerns older iOS releases, while the broader patch coverage indicates that vulnerable CoreGraphics code exists across multiple Apple platforms. It does not establish that exploitation occurred on iPads or Macs.
Targeted users face the highest immediate risk
Apple’s wording points to a focused operation rather than indiscriminate exploitation. Describing an attack as highly sophisticated and directed at specific individuals is consistent with carefully selected targets, although Apple has not attributed the activity to any operator or named the affected group.
The absence of a public exploit does not reduce the need to patch. Once a vulnerability is documented and corrected, attackers can compare patched and unpatched components to identify the relevant code changes. That process can accelerate independent exploit development.
Users should install the applicable update through the normal operating-system update mechanism. Organizations managing Apple fleets should verify the resulting version rather than relying solely on whether an update command was issued.
There is no disclosed workaround for systems that cannot be upgraded. No indicators of compromise, malicious filenames, hashes, domains or process patterns have been published, leaving defenders without vulnerability-specific artifacts to search for.
For potentially exposed high-risk users, ordinary endpoint review may also be insufficient. The available information does not identify where exploitation evidence would appear or whether a successful attack would leave durable traces.
CVE-2026-86950 is not reported in CISA’s KEV catalog
As of September 28, 2026, CVE-2026-86950 has no reported entry in the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog. Consequently, there is no KEV remediation deadline associated with this flaw.
That status should not be confused with Apple’s own statement. The company says it knows of a report that the vulnerability may have been exploited, but CISA has not listed it under the KEV program in the available data.
A KEV listing is operationally significant for US federal civilian agencies because it creates a binding remediation timetable under CISA directives. Its absence does not mean exploitation did not occur, particularly when a vendor has already acknowledged a report involving targeted attacks.
An earlier Apple memory flaw reached the KEV catalog
The case follows another Apple memory-corruption vulnerability associated with sophisticated targeting. CVE-2026-20700 affects dyld, Apple’s dynamic linker, and may permit an attacker who already has memory-write capability to execute arbitrary code.
CVE-2026-20700 has a CVSS 3.1 score of 7.8 and the vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NVD classifies it as CWE-119 and lists these affected version ranges:
- Apple iPadOS before 26.3
- iPhone OS before 26.3
- macOS before 26.3
- tvOS before 26.3
- visionOS before 26.3
- watchOS before 26.3
Apple fixed that vulnerability in iOS and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3 and watchOS 26.3. The exact date of that earlier update is not known.
CISA added CVE-2026-20700 to the KEV catalog on 2026-02-12 and set a remediation deadline of 2026-03-05 for US federal agencies. CISA required agencies to apply vendor mitigations, follow applicable BOD 22-01 guidance for cloud services, or discontinue the product when mitigations were unavailable.
Two other Apple vulnerabilities were issued in connection with the same reported campaign: CVE-2025-14174 and CVE-2025-43529. Both have CVSS scores of 8.8 and the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.
CVE-2025-14174 entered KEV on 2025-12-12, with a federal remediation deadline of 2026-01-02. CVE-2025-43529 followed on 2025-12-15, with a deadline of 2026-01-05. For both, CISA prescribed vendor mitigations, applicable BOD 22-01 measures for cloud services, or discontinuation when no mitigation was available.
CVE-2026-86950 therefore arrives against an established pattern: Apple memory-safety defects have been connected to advanced targeting, and several related vulnerabilities have subsequently triggered mandatory federal remediation. For the newest CoreGraphics flaw, installing the available updates remains the only disclosed defensive action.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2025-43529High8.8A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to arbitrary code execution.
- CVE-2025-14174High8.8Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-86950High8.8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have bee
- CVE-2026-20700High7.8A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issu




