Apple CoreGraphics CVE-2026-86950: Arbitrary Code Execution via Crafted File Processing, with Exploitation Reported
1. Basic Information Article Title : About the security content of iOS 26.7.1 and iPadOS 26.7.1 Publisher : Apple Release Date : 2026-09-28 Original Source : Apple Related Information Sources : Apple: macOS Tahoe 26.7.1 , Apple: macOS Sequoia 15.8.1 , BleepingComputer , CISA KEV catalog data Related Malware, Threat Groups, CVEs, Products : CVE-2026-86950, CoreGraphics, iOS, iPadOS, macOS Tahoe,…
Apple has released a critical security update to address a vulnerability in the CoreGraphics framework of iOS and iPadOS versions prior to 27. This issue, identified as CVE-2026-86950, allows for arbitrary code execution when a specially crafted file is processed by the affected software.
Apple is aware that this vulnerability may have been exploited in targeted attacks against specific individuals using vulnerable versions of iOS and iPadOS. While the exact delivery methods and post-exploitation actions remain undisclosed, successful exploitation can lead to arbitrary code execution on the affected device.
Affected users should immediately update their devices to the latest patched versions of iOS and iPadOS, including iOS 26.7.1 and iPadOS 26.7.1. Additionally, administrators should monitor for signs of the vulnerability being exploited, such as application crashes or reboots, and use mobile device management (MDM) tools to identify and remediate unpatched devices.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.