Back
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
SiTech AI Team2 წთ. საკითხავი

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Apple has released updates for iOS, iPadOS and macOS to close CVE-2026-86950, an out-of-bounds write in CoreGraphics that can lead to code execution from a maliciously crafted file.

Apple has released security updates for older versions of iOS, iPadOS and macOS to address a vulnerability in the CoreGraphics component that the company said may have been exploited in targeted attacks.

An out-of-bounds write in CoreGraphics

The flaw is tracked as CVE-2026-86950 and described as an out-of-bounds write that can lead to arbitrary code execution when a device processes a maliciously crafted file. Apple said the issue was addressed with improved bounds checking and credited Meta Product Security with discovering and reporting it.

"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27," the company said. It did not say how many people were targeted, whether any of those attempts succeeded, or when the first instance of exploitation occurred.

Which devices are affected

The fixes ship in iOS 26.7.1 and iPadOS 26.7.1, covering iPhone 11 and later, iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later) and iPad mini (5th generation and later). Apple also published macOS Tahoe 26.7.1 for Macs running macOS Tahoe and macOS Sequoia 15.8.1 for Macs running macOS Sequoia.

Few details, a familiar pattern

In February 2026 Apple patched a memory corruption issue in the dyld loader, tracked as CVE-2026-20700 with a CVSS score of 7.8, which it said had been weaponized in sophisticated cyber attacks. As in that case, the company has shared little technical detail about CVE-2026-86950, so the practical risk is hard to measure. Users on the affected versions can install the update through the usual software update mechanism.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.