NG Solution Team
Cybersecurity

CVE-2026-86950: Apple fixes zero-day in Core Graphics

Apple has released security updates for iOS and macOS to address an actively exploited zero-day, CVE-2026-86950, in the operating systems’ Core Graphics framework.

“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27,” the company said, but provided no further details about the attacks or the targets.

Core Graphics handles path-based drawing, transformations, color management, offscreen rendering, patterns, gradients and shadings, image data management, image creation, and image masking, as well as PDF document creation, display, and parsing.

Reported by Meta Product Security, CVE-2026-86950 is an out-of-bounds write issue that can allow arbitrary code execution when a vulnerable OS processes a maliciously crafted file.

CVE-2026-86950 affected versions and fixes

A fix for the flaw is included in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Apple’s latest operating systems — iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 — do not appear to be affected: those updates were shipped with no published CVE-numbered vulnerabilities.

Nevertheless, all users should upgrade to a fixed version as soon as possible.

Related Apple news

In other Apple-related news: Apple’s new iOS 27 feature looks for signs you’re being scammed; Apple parental controls in iOS 27 let kids ask before opening new websites; and Apple is building photo verification for the people who need it most.

Related posts

Colorado water cybersecurity breach affected two small providers

Emily Brown

Kenya restores president’s website after Bitcoin ransom hack

James Smith

Could a cybersecurity breach affect 3 million Texas license holders?

Emily Brown

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy