Apple Fixes Zero-Day Exploited in Highly Targeted iPhone Attacks
Apple has released security updates to fix a zero-day vulnerability in its CoreGraphics framework that was exploited in a highly sophisticated, targeted attack against iPhone users.
Apple zero-day allowed arbitrary code execution
Tracked as CVE-2026-86950, the flaw is an out-of-bounds write vulnerability discovered by Meta Product Security. CoreGraphics is used for 2D vector graphics, image rendering, and text drawing across iOS, macOS, iPadOS, watchOS, and tvOS.
An attacker who successfully exploited the vulnerability could crash an application, corrupt data, or potentially achieve remote code execution by writing data outside an allocated memory buffer.
“Apple is aware of reports that this issue may have been exploited in highly sophisticated attacks against specific targeted individuals on versions of iOS prior to iOS 27,” Apple warned on Monday.
Apple said that processing a maliciously crafted file could lead to arbitrary code execution. The company addressed the issue with improved bounds checking.
Apple devices affected by the security flaw
The zero-day affects a broad range of older and newer Apple devices, including:
- iPhone 11 and later
- iPad Pro 12.9-inch, 3rd generation and later
- iPad Pro 11-inch, 1st generation and later
- iPad Air, 3rd generation and later
- iPad, 8th generation and later
- iPad mini, 5th generation and later
- Macs running macOS Sequoia 15.8.1 or macOS Tahoe 26.7.1
Apple security updates address the zero-day
Apple fixed the vulnerability in the following security updates:
Although Apple said the flaw was used only in highly targeted attacks, users should install the available security updates promptly to reduce the risk of continued exploitation.
Apple has patched multiple exploited zero-days
This is the second Apple zero-day exploited in the wild since the beginning of the year. The other flaw, an arbitrary code execution vulnerability in dyld—the dynamic linker used by Apple operating systems—was tracked as CVE-2026-20700 and patched in February after being used in highly sophisticated targeted attacks.
Earlier this year, Apple also fixed a high-severity Beats Studio Buds vulnerability, tracked as CVE-2025-20701, that allowed attackers within Bluetooth range to spy on conversations. The company also patched older iPhones and iPads against four vulnerabilities targeted in cyberespionage and cryptocurrency-theft attacks using the Coruna exploit kit.
In 2025, Apple fixed seven additional zero-days exploited in the wild: CVE-2025-24085 in January; CVE-2025-24200 in February; CVE-2025-24201 in March; CVE-2025-31200 and CVE-2025-31201 in April; and CVE-2025-43529 and CVE-2025-14174 in December.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



