Apple has issued security updates to resolve a vulnerability, tracked as CVE-2026-86950, affecting older versions of iOS, iPadOS, and macOS. The flaw is an out-of-bounds write within the CoreGraphics component, which could lead to arbitrary code execution if a maliciously crafted file is processed. Meta Product Security was credited with discovering and reporting the issue to Apple.
Apple indicated that it is aware of reports suggesting this vulnerability may have been exploited in highly sophisticated attacks. These attacks reportedly targeted specific individuals using versions of iOS prior to iOS 27. The company did not provide further details regarding the number of individuals affected, the success rate of such attempts, or the timeline of any exploitation.
The security updates address CVE-2026-86950 by implementing improved bounds checking. The fix has been rolled out for various Apple devices and operating system versions. These include iOS 26.7.1 and iPadOS 26.7.1 for iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. Updates were also released for macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
This incident follows a similar security update in February, when Apple addressed a memory corruption vulnerability in dyld (CVE-2026-20700, CVSS score: 7.8). That flaw was also reported to have been weaponized in sophisticated cyber attacks, indicating a pattern of targeted exploitation against Apple's platforms.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Security researchers released a public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics vulnerability that Apple stated may have been used in targeted attacks. The flaw, patched on September 28, involves a crafted embedded font in a malicious PDF that causes unpatched iPhones and Macs to crash, highlighting a potential zero-click attack vector.
Apple released a security update for iOS 26, iPadOS 26, and macOS 26 to patch a vulnerability that may have been actively exploited. The bug, found in the graphics engine, could allow sophisticated attacks to steal personal data, affecting a large portion of Apple users still on the previous operating system versions.
Apple released security updates for iOS, macOS, iPadOS, watchOS, and tvOS to fix CVE-2026-20700, a CoreGraphics zero-day vulnerability. This out-of-bounds write flaw was exploited in "extremely sophisticated" targeted attacks on iOS devices, allowing arbitrary code execution through maliciously crafted files.
Apple released iOS and macOS updates to patch CVE-2026-86950, an out-of-bounds write issue in the CoreGraphics component that could lead to arbitrary code execution. The vulnerability was reported by Meta and may have been exploited in targeted attacks against specific individuals on older iOS versions.
Apple released security updates for iOS, iPadOS, and macOS to fix a CoreGraphics vulnerability (CVE-2026-86950) that could allow arbitrary code execution. Apple stated the flaw may have been exploited in targeted attacks against specific individuals on older iOS versions. The updates address the issue with improved bounds checking.