Apple released security updates for CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics that can enable arbitrary code execution when a victim processes a maliciously crafted file. Apple said it is aware of reports that the issue may have been used in an “extremely sophisticated” targeted attack against specific individuals running iOS versions before iOS 27; it did not disclose the attackers, victim count, compromise details, or timing.
The company fixed the flaw with improved bounds checking in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1, and credited Meta Product Security with reporting it. Organizations should prioritize deployment across supported Apple endpoints, particularly devices remaining on pre-iOS 27 releases, because exploitation requires only user processing of a malicious file and could result in full confidentiality, integrity, and availability impact.

See which actors are running it and whether you're in range.
1 event from the most recent confirmed update back to the earliest known activity.
Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 to remediate an out-of-bounds write in CoreGraphics that could permit arbitrary code execution when processing a maliciously crafted file. Apple credited Meta Product Security for reporting the issue and said it may have been exploited in an extremely sophisticated attack targeting specific individuals using iOS versions prior to iOS 27.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
7 references tracked. Mallory keeps watching after this page renders.
macrumors.com
Open sourcetidbits.com
Open sourcecvefeed.io
Open sourcethehackernews.com
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourcesupport.apple.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.