NG Solution Team
Cybersecurity

Apple Patches CoreGraphics Zero‑Day Exploited in Targeted Attacks

Apple has issued a security update to fix a CoreGraphics zero‑day, CVE‑2026‑86950, which the company said may have been exploited in an “extremely sophisticated” attack against specific targeted individuals.

In a bulletin dated September 28, Apple credited the discovery to the Meta Product Security team and warned that “processing a maliciously crafted file may lead to arbitrary code execution.” The company added that it is “aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.”

CoreGraphics vulnerability: affected devices and patches

Apple said the vulnerability affects the CoreGraphics rendering framework on iPhone 11 and later; iPad Pro 12.9‑inch 3rd generation and later; iPad Pro 11‑inch 1st generation and later; iPad Air 3rd generation and later; iPad 8th generation and later; and iPad mini 5th generation and later. Macs running macOS Sequoia 15.8.1 and Tahoe 26.7.1 are also thought to be affected.

Apple reported that the flaw has been fixed in iOS 26.7.1 and iPadOS 26.7.1, and in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.

Response and broader context

Andrew Obadiaru, Cobalt’s CISO, urged security teams to use the warning to revisit device governance for high‑value users. “I’d encourage teams to use this as a prompt to review three things,” he said. “How quickly can you enforce a mobile OS update across your fleet, and who is allowed to defer it? Do you have a defined list of high‑risk individuals with stronger device protections enabled? And if one of those phones were compromised, would your incident response plan know what to do with it? Many IR playbooks still stop at the laptop.”

While Apple said high‑value executives may have been targets of this zero‑day, past discoveries have been linked to commercial spyware vendors that advertise exploits to governments and law enforcement. In February 2025, researchers at The Citizen Lab found CVE‑2025‑24200, which Apple said had been exploited “in an extremely sophisticated attack against specific targeted individual.”

Apple also this month patched CVE‑2026‑86869, a critical zero‑click vulnerability that could be triggered via a maliciously crafted iMessage; Apple said that flaw was found and reported to the company before researchers with malicious intent could weaponize it.

Apple provided no further technical details about CVE‑2026‑86950 beyond the fixes and the attribution to Meta Product Security.

Related posts

Trezor Users Targeted via Compromised Email Service

David Jones

RAF Fairford: Several Men Arrested After Security Alert

Jessica Williams

Has Tata Electronics’ cybersecurity breach impacted its business?

Michael Johnson

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy