Apple's CoreGraphics Zero-Day CVE-2026-86950 Hit Pre-iOS 27 Devices, and Three Outlets Count It Differently
Security / news
Apple's CoreGraphics Zero-Day CVE-2026-86950 Hit Pre-iOS 27 Devices, and Three Outlets Count It Differently
Meta's security team reported the out-of-bounds write. CISA listed it the day after Apple's September 28 fixes, while press counts of Apple's 2026 zero-days range from two to seven.

A crafted file processed by CoreGraphics can give an attacker arbitrary code execution on an iPhone 11 or later running iOS 26, Apple said in the advisory for CVE-2026-86950, which it fixed on September 28, 2026 in iOS 26.7.1 and iPadOS 26.7.1. Apple has not said what kind of file was used, or whether the target had to open anything.
The company said it is aware of a report that the flaw "may have been exploited in an extremely sophisticated attack against specific targeted individuals", according to The Register and SecurityWeek. Apple's security releases page lists iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 all dated 28 September 2026.
Patch now: iOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1
The fix is a bounds check. The Register quoted Apple as saying the flaw was addressed with "improved bounds checking". BleepingComputer listed the affected hardware as iPhone 11 and later, iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later) and iPad mini (5th generation and later).

Apple said devices running iOS 27 and macOS Golden Gate 27 are not affected, per SecurityWeek. The targeted attack therefore concerned versions released before iOS 27. A phone that has already moved to iOS 27 needs no action for this bug, and a phone held back on iOS 26 needs the point release.
Who found it, and what Meta would not say
Apple credits Meta Product Security with the report. SecurityWeek said Meta told it the company regularly reports third-party vulnerabilities to vendors, and declined to say whether WhatsApp was part of this attack chain. SecurityWeek wrote of a precedent it did not tie to this case: the 2025 WhatsApp and Apple ImageIO flaws were exploited together in zero-click attacks on fewer than 200 users.
CoreGraphics renders 2D graphics and PDFs across the operating system, so SecurityWeek reasoned that a malicious file could arrive through a web page, an email or a messaging app with automatic previews. That is an inference about the component, not a finding about this attack. No outlet we read has a delivery method from Apple, Meta or a researcher, and nobody has named the people targeted or the group behind it.
CISA's listing and three different counts
CISA added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog on September 29, 2026, labelling it an Apple Multiple Products out-of-bounds write. The alert does not carry its own remediation date; it points federal civilian agencies to Binding Operational Directive 26-04, which asks them to prioritise KEV fixes on publicly exposed assets.
The outlets disagree on how unusual Apple's year is.
| Outlet | What it said about Apple in 2026 |
|---|---|
| The Register | Apple's seventh zero-day patched in 2026 |
| BleepingComputer | The second, after CVE-2026-20700, a dyld flaw patched in February |
| SecurityWeek | The ninth Apple flaw added to the KEV catalog this year |
Those three may all be defensible, since a KEV entry is not always a zero-day and outlets can apply different definitions of the word. SecurityWeek also wrote that the flaw was not yet in KEV, which CISA's own page contradicts as of September 29. We report CISA's page as the record.
For anyone with an iOS 26 device, open Settings, General, Software Update and install 26.7.1. For other recent exploited client-side bugs, see our reports on the Chrome flaw used against NGOs before Chrome shipped the fix and the OnePlus 15 root chain. Apple's advisory gives no technical detail beyond the component and the bounds check.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.