Vulnerabilities · 9h ago

Apple CoreGraphics Zero-Day Is Now in the Wild

CSIRT Italia and Apple say CVE-2026-86950 is being exploited in the wild, moving the CoreGraphics zero-day from a vendor patch to a live attack on iPhone, iPad, and Mac fleets. Apple has already shipped iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.

The bug is an out-of-bounds write in CoreGraphics, the graphics code that renders images and PDFs. A specially crafted file can make the engine write past the memory it was given, which can lead to arbitrary code execution when a device opens or previews the content; that makes ordinary mail, chat, web, or attachment handling the attack path, not an obvious installer or login.

CISA’s KEV listing and the national CERT confirmation compress this into a days-not-weeks problem for Apple fleets. If users routinely preview shared content on managed devices, the exposure sits in the content-processing layer itself, and the remaining question is how widely the exploit has spread, not whether the flaw is live.

CVE-2026-86950

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: an out-of-bounds write issue was addressed with improved bounds checking.

CISA federal remediation date Oct 2

Timeline

Sources

8 sources covering this story

Entities

Part of the PlainSec briefing for 2026-09-30

Editions

Related stories