
Apple has released emergency security updates to fix CVE-2026-86950, a zero-day vulnerability in CoreGraphics — the low-level Apple framework that handles 2D graphics rendering across iPhone, iPad, Mac, Apple Watch, and Apple TV. The flaw is an out-of-bounds write, meaning software can be tricked into writing data past the boundary of its allocated memory, potentially allowing an attacker to crash a device or execute malicious code. Apple says it has received a report that the bug was exploited in “extremely sophisticated” targeted attacks against specific individuals running iOS versions prior to iOS 27. Meta Product Security discovered and reported the flaw.
Because CoreGraphics processes many types of files — images, PDFs, and other documents — the attack surface is broad: opening a specially crafted file is enough to trigger the vulnerability. Apple has addressed the issue in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. While the known attacks appear to be highly targeted rather than wide-scale, the nature of the flaw (one malicious file → code execution) makes prompt patching critical for everyone.
How to check if you’re affected
Affected devices include iPhone 11 and later, iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later), iPad mini (5th generation and later), and Macs running macOS Sequoia or Tahoe. Affected versions are any iOS or iPadOS release older than 26.7.1, and any macOS Sequoia older than 15.8.1 or macOS Tahoe older than 26.7.1.
To update: go to Settings → General → Software Update on iPhone or iPad, or System Settings → General → Software Update on Mac. Install iOS 26.7.1 / iPadOS 26.7.1 or macOS Tahoe 26.7.1 / macOS Sequoia 15.8.1 to close the vulnerability.
