Published on September 30, 2026
Apple CoreGraphics Zero-Day Vulnerability Actively Exploited in Attacks
Severity
High
Detail
Apple has released iOS 26.7.1 and iPadOS 26.7.1 to address a critical zero-day vulnerability affecting the CoreGraphics framework. Tracked as CVE-2026-86950, the vulnerability may have been exploited in an extremely sophisticated attack targeting specific individuals.
The vulnerability resides in CoreGraphics, a core Apple framework responsible for rendering graphics, images, and documents across iPhone and iPad devices. The flaw is caused by an out-of-bounds write condition that could allow attackers to execute arbitrary code by convincing a victim to process a specially crafted file.
According to Apple, successful exploitation could allow arbitrary code execution on an affected device. Apple confirmed that it is aware of reports indicating that the vulnerability may have been exploited against specifically targeted individuals running versions of iOS prior to iOS 27.
While Apple did not disclose technical details regarding the attacks, zero-day vulnerabilities of this nature are often associated with targeted espionage, surveillance, or attacks against high-value individuals, including executives, government personnel, journalists, activists, and security researchers.
| CVE ID | Summary | Severity |
| CVE-2026-86950 | An out-of-bounds write vulnerability in Apple’s CoreGraphics framework that could allow a specially crafted file to trigger arbitrary code execution on vulnerable devices. Apple has confirmed reports of active exploitation in targeted attacks. | 8.8 (High) |
Affected Products
The vulnerability affects the following devices running vulnerable versions of iOS and iPadOS prior to iOS 26.7.1 and iPadOS 26.7.1:
- iPhone 11 and later.
- iPad Pro 12.9-inch (3rd generation and later).
- iPad Pro 11-inch (1st generation and later).
- iPad Air (3rd generation and later).
- iPad (8th generation and later).
- iPad mini (5th generation and later).
Recommendation
Organizations should implement the following measures immediately to reduce the risk of exploitation:
- Update affected devices to iOS 26.7.1 or iPadOS 26.7.1 or later.
- Prioritize patching devices used by executives, administrators, and other high-value personnel.
- Verify update deployment through Mobile Device Management (MDM) platforms.
- Review security logs and monitoring alerts for signs of suspicious file processing activity.
- Educate users to avoid opening unexpected files or attachments received through untrusted sources.
- Ensure devices remain enrolled in organizational security monitoring and compliance policies.
Source
https://cybersecuritynews.com/apple-zero-day-vulnerability-exploited/
https://support.apple.com/en-us/149226
