Apple Fixes CoreGraphics Bug Reportedly Used in Targeted Attacks
Apple has released security updates fixing a vulnerability in older versions of iOS, iPadOS and macOS, warning it may have already been used in targeted attacks. The flaw, tracked as CVE-2026-86950, is an out-of-bounds write in the CoreGraphics component that could allow attackers to run arbitrary code when a device processes a specially crafted malicious file. Apple credited Meta Product Security with discovering and reporting the issue, and says it was fixed through improved bounds checking.
Apple stated it is aware of a report suggesting the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals using versions before iOS 27. The company has not shared how many people were affected, whether any attempts succeeded, or when exploitation first began. This follows Apple's earlier fix in February for a separate memory corruption flaw in dyld (CVE-2026-20700), which it also said had been used in sophisticated attacks.
While Apple describes this as a targeted attack likely aimed at high-value individuals rather than the general public, all users of affected devices should still update promptly, since patches close off a real code execution risk.