Urgent.News

What's breaking now, across thousands of outlets.

Tech

Apple patches CoreGraphics zero-day already exploited in targeted attacks

Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file

Apple patches CoreGraphics zero-day already exploited in targeted attacks

Apple has released a security patch for a zero-day vulnerability in its CoreGraphics framework, CVE-2026-86950, which was reportedly exploited in targeted attacks against specific individuals running older versions of iOS. The flaw, tracked by Meta Product Security, allows for arbitrary code execution through the processing of maliciously crafted files.

Apple addressed the issue with improved bounds checking in the updated iOS 26.7.1 and iPadOS 26.7.1. The vulnerability affected devices running iOS versions prior to iOS 27, including the iPhone 11 and later, iPad Pro 12.9-inch (third generation and later), iPad Pro 11-inch (first generation and later), iPad Air (third generation and later), iPad (eighth generation and later), and iPad mini (fifth generation and later).

Despite the lack of detailed information on the extent of the attacks, Apple emphasized the importance of installing the update promptly to mitigate potential risks.

Brief written by urgent.news from The Register Science's own syndicated text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

Destroy Any Website

Desktop only, and you definitely want sound on. With things like this I always start with Kottke.org. No idea why, because it’s quite possibly the last site on the entire web I’d want to see actually…

More from Tuesday 29 September →