An out-of-bounds write flaw in iOS/iPadOS/macOS requires urgent patching; the attack method and number of people affected remain undisclosed
On 29 September 2026, Apple released emergency security updates to fix a zero day vulnerability in its CoreGraphics framework that may have been exploited in an “extremely sophisticated attack against specific targeted individuals” using older versions of iOS.
The flaw, tracked as CVE-2026-86950, is an out-of-bounds write bug that could allow arbitrary code execution when a device processes a maliciously crafted file. The issue has been addressed with improved bounds checking in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. The firm’s newest operating systems — iOS 27, iPadOS 27, and macOS Golden Gate 27 — do not appear to be vulnerable to the flaw.
The vulnerability, reported by Meta Product Security, has drawn attention given a similar chain of events last year. In 2025, WhatsApp had disclosed that a vulnerability in its iOS and macOS apps (CVE-2025-55177) was likely used alongside an Apple ImageIO zero day in zero-click attacks targeting fewer than 200 users. It remains unclear whether the newly patched CoreGraphics flaw was exploited through WhatsApp or another vector.
Because CoreGraphics handles 2D graphics and PDF rendering across the operating system, a malicious file could arrive via web pages, email attachments, or messaging apps where automatic previews could enable zero-click exploitation. Apple has not disclosed how many individuals have been targeted; whether any attacks succeeded; or when exploitation first occurred, according to news sources.
Links to previous sophisticated attacks?
CVE-2026-86950 is the second zero day Apple has patched this year that was linked to “extremely sophisticated” targeted attacks. In February this year, the firm had fixed CVE-2026-20700, a memory corruption issue in the dynamic linker in macOS and iOS. The disclosure also follows a September report from the SHARE Foundation, a Serbian civil society organisation, which had found that at least 14 people in Serbia had been targeted with Pegasus spyware since the beginning of 2026 using zero-click exploits.
Apple has not drawn a direct connection between those attacks and CVE-2026-86950. CISA has yet to add the vulnerability to its Known Exploited Vulnerabilities catalog. The firm has urged all users to install the updates promptly.
CoreGraphics presents an attractive attack surface because it is invoked automatically in many common scenarios, from opening a message preview in WhatsApp to viewing a document attachment in Mail. The fact that Meta’s security team identified the issue suggests that the firm’s internal telemetry or threat intelligence may have detected anomalous behavior consistent with exploitation attempts, although neither Apple nor Meta has provided specifics on the attribution or the identity of the threat actor.
Enterprise and high-risk users have been advised to maintain up-to-date devices even when the perceived threat appears limited to a small number of individuals. Apple’s decision to backport the fix to older operating system versions indicates that the vulnerability affects a broad swath of the installed base, and the characterisation of the flaw exploitation as “extremely sophisticated” suggests capabilities typically associated with well-resourced adversaries.
Organisations should verify that all managed devices are running the latest available security updates and consider additional mitigations such as Lockdown Mode for users that may be at elevated risk of targeted cyberattacks.
