Apple squashes zero-day bug exploited in "extremely sophisticated" attack (CVE-2026-86950) - Help Net Security
Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core Graphics framework.

Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core Graphics framework.
the company said, but refrained from providing additional details about the attacks or targets.
Core Graphics handles Reported by Meta Product Security, CVE-2026-86950 is an out-of-bounds write issue that allows for arbitrary code execution when a vulnerable OS processes a maliciously crafted file.
Apple’s new iOS 27 feature looks for signs you’re being scammed Apple parental controls in iOS 27 let kids ask before opening new websites Apple is building photo verification for the people who need it most
Apple’s latest operating systems – iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 don’t appear to be affected: those updates were shipped with no published CVE-numbered vulnerabilities.
Nevertheless, all users should upgrade to a fixed version as soon as possible.
A fix for the flaw is included in iOS 26.7.1, iPadOS 26.7.1 , macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 .
What happened
Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core Graphics framework.
the company said, but refrained from providing additional details about the attacks or targets.
Core Graphics handles Reported by Meta Product Security, CVE-2026-86950 is an out-of-bounds write issue that allows for arbitrary code execution when a vulnerable OS processes a maliciously crafted file.
What changed
Apple’s new iOS 27 feature looks for signs you’re being scammed Apple parental controls in iOS 27 let kids ask before opening new websites Apple is building photo verification for the people who need it most
Who is affected
Apple’s latest operating systems – iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 don’t appear to be affected: those updates were shipped with no published CVE-numbered vulnerabilities.
Nevertheless, all users should upgrade to a fixed version as soon as possible.
Response
A fix for the flaw is included in iOS 26.7.1, iPadOS 26.7.1 , macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 .
Attribution
Help Net Security: Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core Graphics framework.
What to watch next
Watch for additional victim details, indicators of compromise and follow-on exploitation reports.
Watch for revised vendor guidance, fixed versions and mitigation updates.