← All stories
● Covered by 4 sources · 5 reportsMedium impact5 neutral

Apple Patches CoreGraphics Vulnerability Potentially Exploited in Targeted Attacks

🔄 Updated 1d ago — new reporting from The Hacker News
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Apple patched CVE-2026-86950 in CoreGraphics.
  • Vulnerability allowed arbitrary code execution via crafted files.
  • Apple stated it may have been exploited in targeted attacks.
  • Updates released for iOS, iPadOS, and macOS.
  • CVE-2026-86950 is an out-of-bounds write issue.
  • Meta's product security team reported the vulnerability.
  • Exploitation may have occurred on iOS versions before iOS 27.
  • Apple patched CVE-2026-20700, not CVE-2026-86950.
  • Updates released for watchOS and tvOS.
  • Vulnerability exploited in "extremely sophisticated" targeted attacks.
  • CoreGraphics is used for 2D vector graphics, image rendering, text drawing.
  • Improved bounds checking addressed the out-of-bounds write issue.
  • Impacted devices include iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later.
  • Updates released for iOS 26, iPadOS 26, and macOS 26.
  • A public proof-of-concept for CVE-2026-86950 was released.
  • The flaw was patched on September 28.
  • The crafted embedded font in a malicious PDF causes unpatched iPhones and Macs to crash.
  • The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its KEV catalog.
  • Federal agencies must apply the fix by October 2.
  • The analysis was published September 30 by Dion Blazakis, Josh Maine, and Anna Groza of Calif.

CoreGraphics Vulnerability Addressed

Apple has issued security updates to resolve a vulnerability, tracked as CVE-2026-86950, affecting older versions of iOS, iPadOS, and macOS. The flaw is an out-of-bounds write within the CoreGraphics component, which could lead to arbitrary code execution if a maliciously crafted file is processed. Meta Product Security was credited with discovering and reporting the issue to Apple.

Potential Exploitation in Targeted Attacks

Apple indicated that it is aware of reports suggesting this vulnerability may have been exploited in highly sophisticated attacks. These attacks reportedly targeted specific individuals using versions of iOS prior to iOS 27. The company did not provide further details regarding the number of individuals affected, the success rate of such attempts, or the timeline of any exploitation.

Affected Devices and Operating Systems

The security updates address CVE-2026-86950 by implementing improved bounds checking. The fix has been rolled out for various Apple devices and operating system versions. These include iOS 26.7.1 and iPadOS 26.7.1 for iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. Updates were also released for macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.

Prior Security Incidents

This incident follows a similar security update in February, when Apple addressed a memory corruption vulnerability in dyld (CVE-2026-20700, CVSS score: 7.8). That flaw was also reported to have been weaponized in sophisticated cyber attacks, indicating a pattern of targeted exploitation against Apple's platforms.

Updates

🕒 2026-10-01 · new reporting from The Hacker News
  • A public proof-of-concept for CVE-2026-86950 was released.
  • The flaw was patched on September 28.
  • The crafted embedded font in a malicious PDF causes unpatched iPhones and Macs to crash.
  • The U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its KEV catalog.
  • Federal agencies must apply the fix by October 2.
  • The analysis was published September 30 by Dion Blazakis, Josh Maine, and Anna Groza of Calif.
🕒 2026-09-29 · new reporting from TechCrunch
  • Updates released for iOS 26, iPadOS 26, and macOS 26.
🕒 2026-09-29 · new reporting from BleepingComputer
  • Apple patched CVE-2026-20700, not CVE-2026-86950.
  • Updates released for watchOS and tvOS.
  • Vulnerability exploited in "extremely sophisticated" targeted attacks.
  • CoreGraphics is used for 2D vector graphics, image rendering, text drawing.
  • Improved bounds checking addressed the out-of-bounds write issue.
  • Impacted devices include iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later.
🕒 2026-09-29 · new reporting from SecurityWeek
  • CVE-2026-86950 is an out-of-bounds write issue.
  • Meta's product security team reported the vulnerability.
  • Exploitation may have occurred on iOS versions before iOS 27.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Security researchers released a public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics vulnerability that Apple stated may have been used in targeted attacks. The flaw, patched on September 28, involves a crafted embedded font in a malicious PDF that causes unpatched iPhones and Macs to crash, highlighting a potential zero-click attack vector.

Apple released a security update for iOS 26, iPadOS 26, and macOS 26 to patch a vulnerability that may have been actively exploited. The bug, found in the graphics engine, could allow sophisticated attacks to steal personal data, affecting a large portion of Apple users still on the previous operating system versions.

Apple released security updates for iOS, macOS, iPadOS, watchOS, and tvOS to fix CVE-2026-20700, a CoreGraphics zero-day vulnerability. This out-of-bounds write flaw was exploited in "extremely sophisticated" targeted attacks on iOS devices, allowing arbitrary code execution through maliciously crafted files.

Apple released iOS and macOS updates to patch CVE-2026-86950, an out-of-bounds write issue in the CoreGraphics component that could lead to arbitrary code execution. The vulnerability was reported by Meta and may have been exploited in targeted attacks against specific individuals on older iOS versions.

Apple released security updates for iOS, iPadOS, and macOS to fix a CoreGraphics vulnerability (CVE-2026-86950) that could allow arbitrary code execution. Apple stated the flaw may have been exploited in targeted attacks against specific individuals on older iOS versions. The updates address the issue with improved bounds checking.