Apple Patches a CoreGraphics Zero-Day Exploited in Extremely Sophisticated iPhone Attacks
Apple fixed a CoreGraphics flaw that let a malicious file run code on iPhones, iPads, and Macs, and says it may have been used against specific targeted people.

A single booby-trapped file may have been enough to take over targeted iPhones. Apple has now shipped patches for the bug, a flaw in its CoreGraphics framework tracked as CVE-2026-86950.
The issue is an out-of-bounds write. Processing a maliciously crafted file could let an attacker run arbitrary code on the device. Apple fixed it with improved bounds checking, and credited Meta Product Security with discovering and reporting it.
The alarming part is Apple's own wording. The company said it is aware of a report that the flaw may have been exploited in an "extremely sophisticated attack against specific targeted individuals" on versions of iOS before iOS 27. That phrasing usually points to spyware-grade operations aimed at a small number of people, not a mass campaign. Apple gave no victim count and no timeline.
The fixes ship in iOS 26.7.1 and iPadOS 26.7.1, covering the iPhone 11 and later plus the listed iPads, along with macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Anyone still on an older release line is the exposed population here.
The bug marks Apple's second in-the-wild zero-day of 2026, after a dyld flaw (CVE-2026-20700) patched in February. It also lands in a busy month for exploited bugs, weeks after Google rushed out a fix for an actively exploited Chrome V8 flaw.
Image and file parsers like CoreGraphics remain a favourite target because they process content before a user decides anything. The fix is out, and the update is the whole defence.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free