Vulnerabilities · 9h ago
Apple CoreGraphics Zero-Day Is Now in the Wild CSIRT Italia and Apple say CVE-2026-86950 is being exploited in the wild, moving the CoreGraphics zero-day from a vendor patch to a live attack on iPhone, iPad, and Mac fleets. Apple has already shipped iOS 26.7.1 , iPadOS 26.7.1 , macOS Tahoe 26.7.1 , and macOS Sequoia 15.8.1 .
The bug is an out-of-bounds write in CoreGraphics, the graphics code that renders images and PDFs. A specially crafted file can make the engine write past the memory it was given, which can lead to arbitrary code execution when a device opens or previews the content; that makes ordinary mail, chat, web, or attachment handling the attack path, not an obvious installer or login.
CISA’s KEV listing and the national CERT confirmation compress this into a days-not-weeks problem for Apple fleets. If users routinely preview shared content on managed devices, the exposure sits in the content-processing layer itself, and the remaining question is how widely the exploit has spread, not whether the flaw is live.
NVD KEV
Known exploited · CISA KEV
CVSS 8.8 HIGH: an out-of-bounds write issue was addressed with improved bounds checking.
CISA federal remediation date Oct 2
Timeline Sources 8 sources covering this story
Dark Reading Sep 29
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
The Register Security Sep 29
Apple patches CoreGraphics zero-day already exploited in targeted attacks
Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file
TechCrunch Security Sep 29
Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix | TechCrunch
Apple says the bug was used to attack "specific targeted individuals" running iOS 26, which the majority of Apple customers are still using.
Help Net Security Sep 29
Apple squashes zero-day bug exploited in "extremely sophisticated" attack (CVE-2026-86950) - Help Net Security
Apple ships iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in Core Graphics framework.
CSIRT Italia / ACN Sep 29
Apple: rilevato sfruttamento in rete della CVE-2026-86950
Rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2026-86950 – già sanata dal vendor - che interessa i prodotti Apple iOS, iPadOS, macOS Tahoe e macOS Sequoia.
SecurityWeek Sep 29
Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’
Apple has released iOS and macOS updates to patch the zero-day vulnerability tracked as CVE-2026-86950.
SANS ISC Sep 29
Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950)
Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), Author: Johannes Ullrich
The Hacker News Sep 28
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple patched CVE-2026-86950, a CoreGraphics flaw that may have been exploited in targeted attacks via maliciously crafted
Entities Part of the PlainSec briefing for 2026-09-30
Editions Related stories
Vulnerabilities · 9h ago
Apple CoreGraphics Zero-Day Is Now in the Wild CSIRT Italia and Apple say CVE-2026-86950 is being exploited in the wild, moving the CoreGraphics zero-day from a vendor patch to a live attack on iPhone, iPad, and Mac fleets. Apple has already shipped iOS 26.7.1 , iPadOS 26.7.1 , macOS Tahoe 26.7.1 , and macOS Sequoia 15.8.1 .
The bug is an out-of-bounds write in CoreGraphics, the graphics code that renders images and PDFs. A specially crafted file can make the engine write past the memory it was given, which can lead to arbitrary code execution when a device opens or previews the content; that makes ordinary mail, chat, web, or attachment handling the attack path, not an obvious installer or login.
CISA’s KEV listing and the national CERT confirmation compress this into a days-not-weeks problem for Apple fleets. If users routinely preview shared content on managed devices, the exposure sits in the content-processing layer itself, and the remaining question is how widely the exploit has spread, not whether the flaw is live.
NVD KEV
Known exploited · CISA KEV
CVSS 8.8 HIGH: an out-of-bounds write issue was addressed with improved bounds checking.
CISA federal remediation date Oct 2
Timeline Sources 8 sources covering this story
Dark Reading Sep 29
Apple Zero-Day Vulnerability Weaponized in Targeted Attacks
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
The Register Security Sep 29
Apple patches CoreGraphics zero-day already exploited in targeted attacks
Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file
TechCrunch Security Sep 29
Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix | TechCrunch
Apple says the bug was used to attack "specific targeted individuals" running iOS 26, which the majority of Apple customers are still using.
Help Net Security Sep 29
Apple squashes zero-day bug exploited in "extremely sophisticated" attack (CVE-2026-86950) - Help Net Security
Apple ships iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in Core Graphics framework.
CSIRT Italia / ACN Sep 29
Apple: rilevato sfruttamento in rete della CVE-2026-86950
Rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2026-86950 – già sanata dal vendor - che interessa i prodotti Apple iOS, iPadOS, macOS Tahoe e macOS Sequoia.
SecurityWeek Sep 29
Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’
Apple has released iOS and macOS updates to patch the zero-day vulnerability tracked as CVE-2026-86950.
SANS ISC Sep 29
Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950)
Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), Author: Johannes Ullrich
The Hacker News Sep 28
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple patched CVE-2026-86950, a CoreGraphics flaw that may have been exploited in targeted attacks via maliciously crafted
Entities Part of the PlainSec briefing for 2026-09-30
Editions Related stories