Apple Patches Exploited CoreGraphics Zero-Day (CVE-2026-86950) in Older iOS, iPadOS, and macOS Versions
Apple has issued urgent security updates to address a critical zero-day vulnerability, tracked as **CVE-2026-86950**, found in older versions of iOS, iPadOS, and macOS. This flaw, an out-of-bounds write in the **CoreGraphics** component, could enable arbitrary code execution through maliciously crafted files and may have already been exploited in targeted attacks. The tech giant credited **Meta Product Security** for its discovery.

**Apple** has released crucial security updates to address a vulnerability in older iterations of **iOS**, **iPadOS**, and **macOS**. The company stated that this flaw might have been actively exploited in highly targeted attacks.
### Understanding CVE-2026-86950
The vulnerability, identified as **CVE-2026-86950**, is an out-of-bounds write issue affecting the **CoreGraphics** component. If exploited, it could lead to arbitrary code execution when a user processes a specially crafted malicious file.
**Apple** confirmed that the issue has been mitigated through improved bounds checking. The discovery and reporting of this critical flaw were attributed to **Meta Product Security**.
### Targeted Exploitation Concerns
While **Apple** acknowledged reports of **CVE-2026-86950** being exploited in "extremely sophisticated attack[s] against specific targeted individuals on versions of iOS before iOS 27," the company has not provided further details. Information regarding the number of targeted individuals, the success rate of these attacks, or the timeline of initial exploitation remains undisclosed.
### Affected Devices and OS Versions
Security patches have been rolled out for the following devices and operating system versions:
* **iOS 26.7.1 and iPadOS 26.7.1**: Applicable to **iPhone 11** and later, **iPad Pro 12.9-inch 3rd generation** and later, **iPad Pro 11-inch 1st generation** and later, **iPad Air 3rd generation** and later, **iPad 8th generation** and later, and **iPad mini 5th generation** and later.
* **macOS Tahoe 26.7.1**: For Macs running **macOS Tahoe**.
* **macOS Sequoia 15.8.1**: For Macs running **macOS Sequoia**.
This incident follows a similar pattern from February, when **Apple** addressed another memory corruption issue in **dyld** (**CVE-2026-20700**, CVSS score: 7.8), which had also been weaponized in sophisticated cyber attacks.