Apple Fixes CoreGraphics Vulnerability Potentially Used in Targeted Attacks

Apple Fixes CoreGraphics Vulnerability Potentially Used in Targeted Attacks

Apple has issued security updates to rectify a flaw in older versions of iOS, iPadOS, and macOS, which it indicated might have been utilized in targeted attacks.

The flaw, identified as CVE-2026-86950, pertains to an out-of-bounds write affecting the CoreGraphics component, potentially allowing arbitrary code execution when handling a maliciously crafted file.

The company stated that the issue was resolved through enhanced bounds checking and acknowledged Meta Product Security for discovering and reporting the vulnerability.

“Apple is aware of a report suggesting that this vulnerability may have been exploited in a highly sophisticated attack against specific individuals using versions of iOS prior to iOS 27,” it noted.

However, the company did not provide information regarding the number of individuals targeted, whether any of those attempts were successful, or when the first instance of CVE-2026-86950 exploitation took place.

The vulnerability has been addressed in the following devices and operating system versions –

  • iOS 26.7.1 and iPadOS 26.7.1 – iPhone 11 and newer, iPad Pro 12.9-inch 3rd generation and newer, iPad Pro 11-inch 1st generation and newer, iPad Air 3rd generation and newer, iPad 8th generation and newer, and iPad mini 5th generation and newer
  • macOS Tahoe 26.7.1 – Macs operating on macOS Tahoe
  • macOS Sequoia 15.8.1 – Macs running macOS Sequoia

Earlier this February, Apple resolved a memory corruption issue in dyld (CVE-2026-20700, CVSS score: 7.8) that it claimed had been weaponized in advanced cyber attacks.

Source: Original article

Leave a Reply

Your email address will not be published. Required fields are marked *

Back To Top