Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)

Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)
Apple has released security updates for iOS and macOS to address CVE-2026-86950, an actively exploited zero-day in the Core Graphics framework. The flaw could enable arbitrary code execution through a maliciously crafted file, and users are urged to install the fixed versions immediately. #Apple #iOS #macOS #CVE-2026-86950 #CoreGraphics #MetaProductSecurity

Keypoints

  • Apple patched an actively exploited zero-day in Core Graphics.
  • CVE-2026-86950 is an out-of-bounds write vulnerability.
  • A malicious file could trigger arbitrary code execution.
  • Meta Product Security reported the flaw to Apple.
  • Fixes are available in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.

Read More: https://www.helpnetsecurity.com/2026/09/29/apple-core-graphics-zero-day-cve-2026-86950-fixed/