{
  "id": 10708476,
  "title": "Apple patches CoreGraphics zero-day already exploited in targeted attacks",
  "url": "https://urgent.news/2026/09/29/apple-patches-coregraphics-zero-day-already-exploited-in-targeted",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-29T14:30:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/29/apple-patches-coregraphics-zero-day-already-exploited-in-targeted-attacks/5299721"
  },
  "original_language": "en",
  "account": null,
  "summary": "Apple has released a security patch for a zero-day vulnerability in its CoreGraphics framework, CVE-2026-86950, which was reportedly exploited in targeted attacks against specific individuals running older versions of iOS. The flaw, tracked by Meta Product Security, allows for arbitrary code execution through the processing of maliciously crafted files. Apple addressed the issue with improved bounds checking in the updated iOS 26.7.1 and iPadOS 26.7.1. The vulnerability affected devices running iOS versions prior to iOS 27, including the iPhone 11 and later, iPad Pro 12.9-inch (third generation and later), iPad Pro 11-inch (first generation and later), iPad Air (third generation and later), iPad (eighth generation and later), and iPad mini (fifth generation and later). Despite the lack of detailed information on the extent of the attacks, Apple emphasized the importance of installing the update promptly to mitigate potential risks.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Apple patches CoreGraphics zero-day already exploited in targeted attacks",
        "url": "https://urgent.news/2026/09/29/apple-patches-coregraphics-zero-day-already-exploited-in-targeted-10710921",
        "published": "2026-09-29T14:30:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}