{
  "id": 10849896,
  "title": "Apple CoreGraphics CVE-2026-86950: Arbitrary Code Execution via Crafted File Processing, with Exploitation Reported",
  "url": "https://urgent.news/2026/09/30/apple-coregraphics-cve-2026-86950-arbitrary-code-execution-via",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-30T03:50:37.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/anoymask/apple-coregraphics-cve-2026-86950-arbitrary-code-execution-via-crafted-file-processing-with-5ie"
  },
  "original_language": "en",
  "account": "Apple has released a critical security update to address a vulnerability in the CoreGraphics framework of iOS and iPadOS versions prior to 27. This issue, identified as CVE-2026-86950, allows for arbitrary code execution when a specially crafted file is processed by the affected software.\n\nApple is aware that this vulnerability may have been exploited in targeted attacks against specific individuals using vulnerable versions of iOS and iPadOS. While the exact delivery methods and post-exploitation actions remain undisclosed, successful exploitation can lead to arbitrary code execution on the affected device.\n\nAffected users should immediately update their devices to the latest patched versions of iOS and iPadOS, including iOS 26.7.1 and iPadOS 26.7.1. Additionally, administrators should monitor for signs of the vulnerability being exploited, such as application crashes or reboots, and use mobile device management (MDM) tools to identify and remediate unpatched devices.",
  "summary": "1. Basic Information Article Title : About the security content of iOS 26.7.1 and iPadOS 26.7.1 Publisher : Apple Release Date : 2026-09-28 Original Source : Apple Related Information Sources : Apple: macOS Tahoe 26.7.1 , Apple: macOS Sequoia 15.8.1 , BleepingComputer , CISA KEV catalog data Related Malware, Threat Groups, CVEs, Products : CVE-2026-86950, CoreGraphics, iOS, iPadOS, macOS Tahoe,…",
  "key_points": [
    "Apple releases critical security update for iOS and iPadOS",
    "CVE-2026-86950 enables arbitrary code execution via crafted file",
    "Users urged to update to iOS 26.7.1 and iPadOS 26.7.1"
  ],
  "editors_take": "This critical security update marks a significant effort by Apple to mitigate targeted attacks exploiting a high-risk vulnerability in CoreGraphics, requiring immediate action from users and administrators to prevent arbitrary code execution.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}