DKDKCISSPSearch
Vulnerabilities

Apple squashes zero-day bug exploited in "extremely sophisticated" attack (CVE-2026-86950) - Help Net Security

Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core Graphics framework.

DKCISSP News DeskHelp Net Security29 Sept 2026, 3:20 pm
Apple squashes zero-day bug exploited in "extremely sophisticated" attack (CVE-2026-86950) - Help Net Security
Image courtesy of Help Net Security. Original report
DKCISSP REPORT

Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core Graphics framework.

the company said, but refrained from providing additional details about the attacks or targets.

Core Graphics handles Reported by Meta Product Security, CVE-2026-86950 is an out-of-bounds write issue that allows for arbitrary code execution when a vulnerable OS processes a maliciously crafted file.

Apple’s new iOS 27 feature looks for signs you’re being scammed Apple parental controls in iOS 27 let kids ask before opening new websites Apple is building photo verification for the people who need it most

Apple’s latest operating systems – iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 don’t appear to be affected: those updates were shipped with no published CVE-numbered vulnerabilities.

Nevertheless, all users should upgrade to a fixed version as soon as possible.

A fix for the flaw is included in iOS 26.7.1, iPadOS 26.7.1 , macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 .

What happened

Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core Graphics framework.

the company said, but refrained from providing additional details about the attacks or targets.

Core Graphics handles Reported by Meta Product Security, CVE-2026-86950 is an out-of-bounds write issue that allows for arbitrary code execution when a vulnerable OS processes a maliciously crafted file.

What changed

Apple’s new iOS 27 feature looks for signs you’re being scammed Apple parental controls in iOS 27 let kids ask before opening new websites Apple is building photo verification for the people who need it most

Who is affected

Apple’s latest operating systems – iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 don’t appear to be affected: those updates were shipped with no published CVE-numbered vulnerabilities.

Nevertheless, all users should upgrade to a fixed version as soon as possible.

Response

A fix for the flaw is included in iOS 26.7.1, iPadOS 26.7.1 , macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 .

Attribution

Help Net Security: Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core Graphics framework.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN VULNERABILITIES

More cybersecurity reporting

Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmCritical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pm