Apple patches CoreGraphics zero-day already exploited in targeted attacks
Apple has patched a CoreGraphics security flaw after saying it may have been exploited in highly sophisticated attacks against a small number of targeted individuals. The bug could let an attacker run code by getting a vulnerable device to process a maliciously crafted file, raising the possibility it was used in a targeted spyware campaign.
Tracked as CVE-2026-86950, the flaw was reported by Meta Product Security and fixed through improved bounds checking. Apple released fixes in iOS 26.7.1 and iPadOS 26.7.1 for a range of iPhones and iPads, including iPhone 11 and later; it has not disclosed who was targeted, how many people were affected or which earlier iOS versions were involved. This is the seventh zero-day Apple has fixed this year.
- Apple fixed a CoreGraphics flaw that may have been used in targeted attacks.
- A malicious file could potentially enable arbitrary code execution.
- Install iOS or iPadOS 26.7.1 on affected devices.