> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Apple Patches CoreGraphics Zero-Day Linked to Sophisticated Targeted Attacks

[SOURCE] Security Affairs [AUTHOR: Pierluigi Paganini] [DATE: 29/09/2026 13:28] [LANGUAGE: EN]
Apple patched zero-day CVE-2026-86950 in CoreGraphics, exploited in sophisticated targeted attacks against specific iOS users. Apple has released security updates for iOS, iPadOS and macOS to fix a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that may have been exploited in attacks against specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when the system processes a specially crafted file. The vulnerability affects iOS 26.7 and earlier versions before iOS 27, as well as iPadOS 26.7 and earlier and supported versions of macOS Tahoe and macOS Sequoia. Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to address the issue. “Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” reads Apple’s advisory. “Description: “An out-of-bounds write issue was addressed with improved bounds checking.” The more important sentence, however, is the one that turns this from another vulnerability disclosure into a security incident worth watching. Apple says it knows of a report that the flaw may have been exploited in an “extremely sophisticated attack against specific targeted individuals” running versions of iOS before iOS 27. Apple hasn’t disclosed who was targeted, how many people were affected, whether the attacks succeeded, or when exploitation started. It also hasn’t explained how attackers delivered the malicious files. That leaves an important part of the attack chain unknown. CoreGraphics handles graphics and rendering functions across Apple’s operating systems, including processing content such as images and PDFs. Attackers can trigger the flaw by tricking the victim into opening a malicious file sent through a web page, an email attachment, or a messaging application, However, Apple hasn’t confirmed any of these delivery methods for CVE-2026-86950. That distinction matters. A crafted file doesn’t need to look like an obvious executable for a vulnerability in a system component that processes content to become useful to an attacker. The security boundary can be crossed while the operating system is simply doing what it’s designed to do: interpreting a file. Meta Product Security discovered and reported the vulnerability to Apple. The involvement of Meta is particularly interesting because the company has previously identified attacks involving Apple vulnerabilities and targeted users of its messaging platforms. Last year, WhatsApp disclosed that a vulnerability in its iOS and macOS applications, tracked as CVE-2025-55177, was likely chained with Apple’s ImageIO zero-day CVE-2025-43300 in zero-click attacks against fewer than 200 users. There is no evidence that the new CoreGraphics vulnerability was used through WhatsApp, and SecurityWeek reported that it was seeking clarification from Meta. That uncertainty is worth keeping intact. It would be easy to connect the two incidents simply because Meta reported the new Apple flaw, but the available information doesn’t establish that link. The patch itself is also interesting because Apple has fixed the vulnerability in the older operating system branches rather than treating the move to the latest major release as the only answer. Apple released iOS 26.7.1 and iPadOS 26.7.1 for supported iPhones and iPads, while macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 address the problem on Macs. CISA had not yet added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog. This isn’t the first Apple vulnerability this year to carry an exploitation warning. In February, Apple patched CVE-2026-20700, a memory corruption issue in the dynamic linker, or dyld, after reporting that it had been weaponized in sophisticated attacks. The pattern is more relevant than the individual CVE. Attackers targeting a small number of people don’t need a vulnerability that affects millions of devices indiscriminately. They need a reliable flaw in a component that processes content, a way to get that content in front of the target, and an exploitation chain that can survive the platform’s security controls. Back to CVE-2026-86950, Apple did not disclose technical details about the attacks, the identities of the targets, or the threat actors. The practical response is straightforward. Organizations managing Apple devices should identify systems still running affected releases and prioritize the relevant security updates, particularly where devices belong to executives, researchers, journalists, government personnel or other users who may face targeted attacks. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, Apple)
[messages.read_original_source] →