Apple Fixes CoreGraphics Flaw CVE-2026-86950 in iOS 26.7.1 After Meta Reports Targeted Attacks
Security / news
Apple Fixes CoreGraphics Flaw CVE-2026-86950 in iOS 26.7.1 After Meta Reports Targeted Attacks
Apple's entry says a crafted file can run code and that exploitation may have hit specific people on iOS versions before iOS 27, but it names no victims and no attacker.

Apple released iOS 26.7.1 and iPadOS 26.7.1 on Sept. 28 to fix CVE-2026-86950, a CoreGraphics flaw where processing a crafted file can run attacker code, and said it may already have been used against specific people.
Apple's security entry describes an out-of-bounds write, a memory error where code writes past the end of a buffer, that "was addressed with improved bounds checking." The impact line reads "Processing a maliciously crafted file may lead to arbitrary code execution." Apple's description names a file as the trigger, not a link or a network connection.
What Apple says about exploitation
The entry says Apple is aware of a report that the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals" on iOS versions before iOS 27. It credits Meta Product Security, Meta's internal security team, and says nothing further about how the report arose.
Apple has not said who was targeted, how many people were affected or who was behind the attacks, according to The Register's Carly Page, who counted this as Apple's seventh zero-day fix of 2026. A zero-day here means a flaw attacked before a fix existed. No CVSS score appears in the entry.

Dated sequence
- Sept. 28: iOS 26.7.1, iPadOS 26.7.1 and macOS Tahoe 26.7.1 appear on Apple's security releases list, the iOS entry carrying the CoreGraphics fix.
- Sept. 29: CISA adds CVE-2026-86950 to its Known Exploited Vulnerabilities catalog, listing the vendor as Apple and the product as multiple products.
- Sept. 29, 15:30 UTC: The Register publishes its report.
- Oct. 2: federal civilian agencies' deadline under the catalog entry.
The three-day window matches the pattern analysed in our report on CISA's patch deadlines.
Which devices get the fix
The entry covers devices that run iOS 26 or iPadOS 26:
| Device family | Earliest model covered |
|---|---|
| iPhone | iPhone 11 and later |
| iPad Pro 12.9-inch | 3rd generation and later |
| iPad Pro 11-inch | 1st generation and later |
| iPad Air | 3rd generation and later |
| iPad | 8th generation and later |
| iPad mini | 5th generation and later |
Devices outside that list do not appear in the entry. Apple's list for macOS Tahoe 26.7.1 shows the same Sept. 28 date, but its advisory is a separate page, and the iOS advisory page carries the CoreGraphics entry for iOS and iPadOS only. Apple's macOS Tahoe 26.7.1 notes sit on their own page, so Mac owners should read that entry before assuming the same fix applies.
What to do
Apple's flaw joins a month of exploited-before-patched bugs on edge and endpoint software, among them the NetScaler SAML zero-day and the FortiMail flaw with no fixed build.
Install iOS 26.7.1 or iPadOS 26.7.1 through Settings, General, Software Update. Apple's entry does not say whether Meta observed the attacks itself, and it gives no description of the file involved, so there is no indicator to hunt for beyond checking the installed version.
Sources
More in Security
- 01Cling Botnet Hides Commands in the STUN Transaction ID and Spreads Through Realtek Flaw CVE-2021-35394Nozomi Networks says the malware sends traffic that resembles ordinary Google STUN replies, so defenders have to hunt for all-zero transaction IDs instead of blocking an address.
- 02NetScaler SAML Zero-Day CVE-2026-88779 Was Exploited Days After Two Others, and CISA's Deadline Is TodayCitrix rates the flaw 8.7 and calls it a denial of service, but a researcher's honeypot ran a downloaded binary, and appliances patched for last week's bugs need a second upgrade.
- 03Cloudflare's Open-Source Audit Skill Is at 25,900 Stars, but Its Own Post Shows 20,799 Candidates Became 7,245 Actionable FindingsThe repository trending on GitHub is the 450-line starting point. The funnel numbers in Cloudflare's June write-up describe a different system that has not been released.
- 04FortiMail CVE-2026-104286: Unauthenticated File Write Exploited at Disclosure, With No Fixed Build YetFortinet's advisory FG-IR-26-175 lists fixes for 7.4, 7.6 and 8.0 as pending; the interim steps are disabling IBE and closing the management interface.