Apple Patches Actively Exploited CoreGraphics Zero-Day Used in 'Extremely Sophisticated' Attacks
Apple shipped emergency security updates for iOS and macOS on 29 September to address CVE-2026-86950, an out-of-bounds write vulnerability in the CoreGraphics framework that the company says has been exploited in the wild. Apple described the attacks as 'extremely sophisticated' and directed at 'specific targeted individuals' running iOS versions prior to iOS 27.
The CoreGraphics framework handles 2D graphics rendering across Apple's operating systems. The vulnerability affects a broad range of devices, including iPhones dating back to the iPhone 11 and multiple generations of iPads. Apple did not identify the attackers or the targets, nor did it disclose how the vulnerability was discovered.
Security researchers noted that the exploit follows a pattern of highly capable threat actors targeting components that process untrusted content. One analyst drew a comparison to CVE-2025-55177, a WhatsApp vulnerability that was chained with CVE-2025-43300, another out-of-bounds zero-day in Apple's ImageIQ technology, to achieve exploitation.
This is Apple's second zero-day patch of 2026. The first, CVE-2026-20700, was an arbitrary code execution flaw in dyld — the dynamic link editor used by Apple's operating systems — also described as exploited in 'extremely sophisticated' targeted attacks and patched in February. The continued discovery of zero-days in core Apple frameworks underscores that even heavily audited codebases remain vulnerable to well-resourced adversaries.
Source: Dark Reading. This article summarizes the linked reporting and distinguishes announced plans from demonstrated results.