Urgent.News

What's breaking now, across thousands of outlets.

Tech

Apple patches CoreGraphics zero-day already exploited in targeted attacks

Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file

Apple patches CoreGraphics zero-day already exploited in targeted attacks

Apple released a security patch for a critical vulnerability known as CVE-2026-86950 in its CoreGraphics framework, which is used for handling graphics across its operating systems. This zero-day flaw, also referred to as an out-of-bounds write issue, allows attackers to execute arbitrary code on vulnerable devices by processing maliciously crafted files.

Apple disclosed that it was aware of an extremely sophisticated attack targeting specific individuals on iOS versions prior to iOS 27. The company has not disclosed the number of affected users, the identity of the attackers, or the exact exploitation method. The patch was rolled out on Monday in iOS 26.7.1 and iPadOS 26.7.1 and affects devices including the iPhone 11 and later, iPad Pro 12.9-inch (third generation and later), and iPad Air (third generation and later).

Apple's decision to release this patch so quickly highlights the seriousness of the issue and the potential risks posed by this zero-day vulnerability.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

Destroy Any Website

Desktop only, and you definitely want sound on. With things like this I always start with Kottke.org. No idea why, because it’s quite possibly the last site on the entire web I’d want to see actually…

More from Tuesday 29 September →