Apple Patches iOS Zero-Day Used in Targeted Attacks
Apple has issued a fix for CVE-2026-86950, a vulnerability in its CoreGraphics rendering framework that could allow arbitrary code execution when a device processes a maliciously crafted file. The flaw, discovered by Meta's Product Security team, is believed to have been exploited in an "extremely sophisticated" attack targeting specific individuals on versions of iOS before iOS 27. It affects a wide range of iPhones (11 and later), several iPad models, and Macs running macOS Sequoia 15.8.1 and Tahoe 26.7.1.
While most small businesses are not the direct target of this kind of highly targeted attack, security experts note the incident is a useful prompt to review device management practices, particularly for senior staff who may be granted exceptions from standard update policies. Cobalt CISO Andrew Obadiaru suggested organisations check how quickly they can enforce mobile OS updates, whether high-risk staff have stronger protections in place, and whether incident response plans extend beyond laptops to cover mobile devices.
Apple also patched a separate critical zero-click flaw this month, CVE-2026-86869, which could have been triggered through a malicious iMessage without any user interaction. That vulnerability appears to have been reported responsibly before it could be exploited.