Apple Patches a Meta-Reported CoreGraphics Zero-Day Possibly Exploited in Targeted iOS Attacks
Apple fixed CVE-2026-86950, an out-of-bounds write in CoreGraphics reported by Meta Product Security, in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, and says it may have...
Apple has patched a CoreGraphics vulnerability, CVE-2026-86950, that it says may have been exploited in a targeted attack on iOS. The fix shipped on September 28 in iOS 26.7.1 and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, and Apple credits Meta Product Security with reporting the bug. Each advisory carries the same warning: “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.”
Table Of Content
Apple offered no details on how many people were targeted, whether any attempts succeeded, or when exploitation began, as The Hacker News notes, and SecurityWeek adds that Apple has not said how the malicious file is delivered. That leaves defenders with a patch to apply and little public detail to hunt for.
What the advisories say
The bug is an out-of-bounds write in CoreGraphics. Apple’s impact line reads “Processing a maliciously crafted file may lead to arbitrary code execution,” and its description says “An out-of-bounds write issue was addressed with improved bounds checking.” MITRE defines that weakness class, CWE-787, this way: “The product writes data past the end, or before the beginning, of the intended buffer.”
CoreGraphics is the framework Apple’s operating systems use for two-dimensional graphics, as BleepingComputer describes it. Help Net Security lists what it handles: “path-based drawing, transformations, color management, offscreen rendering, patterns, gradients and shadings, image data management, image creation, and image masking, as well as PDF document creation, display, and parsing.” Because CoreGraphics renders graphics and PDFs across the operating system, SecurityWeek points out that a malicious file could arrive through web pages, email attachments or messaging apps, where automatic attachment and link previews could make an exploit zero-click. Apple has not confirmed a delivery route. The NVD record carries a CVSS 3.1 score of 8.8 (High) from a secondary source, and that vector assumes some user interaction is required; NVD’s own analysis is still marked “Awaiting Analysis.”
The exploitation sentence is word for word the same in all three advisories, including the two for macOS, but it speaks only about iOS. The macOS advisories say nothing about attacks on Macs.
Which update you need
iPhone 11 and later are covered by both iOS 26.7.1 and iOS 27. Apple’s security releases page also lists iOS 27.0.1, iPadOS 27.0.1 and macOS Golden Gate 27.0.1, all dated September 28, each with the note “This update has no published CVE entries.” Help Net Security says those builds “don’t appear to be affected,” but Apple has not said whether version 27 was never vulnerable or already carried the fix.
The 26.7.1 branch matters most for older iPads. Apple’s release index lists iPadOS 27 for the iPad Pro 12.9-inch 4th generation and later, iPad Pro 11-inch 2nd generation and later, iPad Air 4th generation and later, iPad 9th generation and later, and iPad mini 6th generation and later. Five models are on the iPadOS 26.7.1 list but not the iPadOS 27 list:
- iPad Pro 12.9-inch, 3rd generation
- iPad Pro 11-inch, 1st generation
- iPad Air, 3rd generation
- iPad, 8th generation
- iPad mini, 5th generation
For those iPads, iPadOS 26.7.1 is the fix. Macs still on macOS Tahoe need 26.7.1, and Macs on macOS Sequoia need 15.8.1.
Why Meta’s name is on the advisory
Apple’s credit line reads “CVE-2026-86950: Meta Product Security.” Meta has appeared in an Apple zero-day story before. In August 2025, WhatsApp said a flaw in WhatsApp for iOS and Mac, CVE-2025-55177, “in combination with an OS-level vulnerability on Apple platforms (CVE-2025-43300), may have been exploited in a sophisticated attack against specific targeted users.” SecurityWeek says those attacks were aimed at fewer than 200 users. The Apple half of that chain, CVE-2025-43300, was also an out-of-bounds write, in Apple’s Image I/O framework, and Apple described it in nearly the same “extremely sophisticated attack” language.
This time there is no confirmed link to WhatsApp. WhatsApp’s 2026 advisory page lists only two entries as of Tuesday, CVE-2026-23866 and CVE-2026-23863, and neither refers to the Apple bug. SecurityWeek says it is unclear whether CVE-2026-86950 was exploited through WhatsApp and that it has asked Meta for clarification. For now, the Meta credit shows who found the bug, not how it was used.
Where it stands in the vulnerability registries
NVD published the record on September 28. CISA’s Known Exploited Vulnerabilities catalog did not list CVE-2026-86950 in the version released September 27, the latest at the time of writing. It would be the ninth Apple entry added this year: the catalog’s eight 2026 Apple additions run from CVE-2026-20700 on February 12 to CVE-2026-65400 on August 18. CISA added the 2025 Image I/O flaw on August 21, 2025, with a September 11 deadline for federal agencies.
One identifier warning: the February dyld zero-day is CVE-2026-20700, which is already in the KEV catalog. As of Tuesday morning, BleepingComputer’s report attached that number to the CoreGraphics bug, but Apple’s credit line and NVD both list CVE-2026-86950.
What to do now
Install the newest update available for your device. On iPhone and iPad, open Settings, tap General, then tap Software Update, as Apple’s update guide describes; turning on Automatic Updates in the same menu keeps future fixes from waiting on you. Anyone managing iPads should look for the five older models above, since they are not on Apple’s iPadOS 27 list.
People who may be personally targeted have another option. Apple describes Lockdown Mode as “an optional, extreme protection that’s designed for the very few individuals who, because of who they are or what they do, might be personally targeted by some of the most sophisticated digital threats.” In Messages, Apple says, “Most message attachment types are blocked, other than certain images, video, and audio,” and features such as links and link previews are unavailable. Apple has not said whether Lockdown Mode would have stopped this exploit, and it advises updating to the latest software before turning it on.
The Image I/O bug in 2025, this CoreGraphics bug and the critical heap overflow in libheif we covered earlier this month are all memory-corruption flaws in code that handles image or document data.








No Comment! Be the first one.