The vulnerability, tracked as CVE-2026-86950, was discovered by Meta Product Security and affects Apple's CoreGraphics framework, which handles two-dimensional vector graphics, image rendering, and text drawing across iOS, iPadOS, macOS, watchOS, and tvOS. Attackers could exploit the out-of-bounds write weakness to crash a program, corrupt data, or achieve remote code execution by writing data outside the allocated memory buffer.
Apple acknowledged the exploitation in a security advisory, stating it was aware of 'a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.' The company did not disclose who was targeted, the scale of the attacks, or the attackers' identity, though the description suggests the bug was used in a targeted spyware campaign rather than widespread exploitation.
The fix has been delivered in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Affected devices include the iPhone 11 and later, several iPad models, and Macs running the specified macOS versions. Apple said the issue was addressed with improved bounds checking.
CVE-2026-86950 marks the seventh zero-day vulnerability Apple has patched this year that was exploited in the wild. Earlier this year, the company fixed a dyld zero-day (CVE-2026-20700) also used in extremely sophisticated targeted attacks, a Beats Studio Buds flaw enabling Bluetooth eavesdropping, and four vulnerabilities exploited by the Coruna exploit kit in cyberespionage and crypto-theft campaigns.
Users are strongly advised to apply the latest updates promptly, even if they believe they are not likely targets, as the patch closes a known attack vector.