Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’ 

Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’ 
Apple has released iOS and macOS updates to fix CVE-2026-86950, a CoreGraphics zero-day that may have been exploited in targeted attacks against specific individuals. The flaw could allow arbitrary code execution through specially crafted files, and Apple says it learned of the issue from Meta’s product security team. #CVE-2026-86950 #CoreGraphics #Apple #Meta

Keypoints

  • Apple patched a zero-day in CoreGraphics tracked as CVE-2026-86950.
  • The flaw could enable arbitrary code execution through a specially crafted file.
  • Apple said the issue may have been used in highly targeted attacks on iOS.
  • Meta’s product security team reported the vulnerability to Apple.
  • The fix is included in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.

Read More: https://www.securityweek.com/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack/