Apple patches CoreGraphics zero-day linked to targeted pre-iOS 27 attacks
Apple released iOS, iPadOS and macOS updates to fix CVE-2026-86950, a CoreGraphics flaw that can enable arbitrary code execution. Apple said the bug may have been used in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
TLDR
Apple has issued iOS, iPadOS and macOS updates for CVE-2026-86950, an out-of-bounds write flaw in CoreGraphics that can allow arbitrary code execution when a specially crafted file is processed. Apple said it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. SecurityWeek reported that Apple credited Meta’s product security team with reporting the vulnerability, and said it remains unclear whether WhatsApp was involved.
Combined views
739
1 Source, first seen 1h ago

