Apple CoreGraphics Zero-Day CVE-2026-86950: iOS 27 Immune, iOS 26 Fleets Get 3 Days
🛡️ Security •

Apple CoreGraphics Zero-Day CVE-2026-86950: iOS 27 Immune, iOS 26 Fleets Get 3 Days

Apple patched an exploited CoreGraphics out-of-bounds write on iOS 26, iPadOS 26 and two macOS branches; iOS 27 was never affected. CISA gave federal agencies until 2 October.

applezero-daycisa keviosmacos

Apple shipped four out-of-band security updates on 28 September 2026 for a single bug: CVE-2026-86950, an out-of-bounds writeOut-of-Bounds Write🛡️A memory-safety bug (CWE-787) in which a program writes data past the beginning or end of the buffer it allocated, corrupting adjacent memory. In file parsers it is typically triggered by a length or offset in attacker-controlled input and can be turned into arbitrary code execution. in CoreGraphics that lets a crafted file execute arbitrary code. Apple says the flaw "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." CISA added it to the Known Exploited Vulnerabilities catalog the next day with a 2 October remediation deadline. The unusual part is the patch matrix: the fix went to the previous-generation OS branches only, because the current branch was never vulnerable.

What Happened

The updates are iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Each carries exactly one CVE entry. Apple's description is terse: "Processing a maliciously crafted file may lead to arbitrary code execution," fixed by "improved bounds checking." Credit goes to Meta Product Security.

The same day Apple also released iOS 27.0.1, iPadOS 27.0.1, macOS Golden Gate 27.0.1, watchOS 27.0.1 and visionOS 27.0.1, but Apple's security releases index lists no published CVE entries for any of them. Apple's security content page for iOS 27 and iPadOS 27, released 14 September with 197 CVEs, does not list CVE-2026-86950 either. Read together with the "before iOS 27" wording, the picture is that the vulnerable code path exists in the 26.x and Sequoia 15.x branches and was already absent or unreachable in the 27 release. TechCrunch reported the same conclusion: users on iOS 27 received an update but are unaffected by the bug under attack.

Neither Apple nor Meta has said how the exploitExploit🛡️Code or technique that takes advantage of a vulnerability to cause unintended behavior, such as gaining unauthorized access. was delivered, how many people were hit, or who was behind it. SecurityWeek asked Meta and got a statement that the company regularly reports vulnerabilities found in third-party software to other vendors, and nothing more. There is no public proof of concept and no campaign-specific indicators of compromise as of this writing.

Who Is Affected

Apple's device list for iOS 26.7.1 and iPadOS 26.7.1 is iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. On the desktop side, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 cover the two branches behind Golden Gate 27.

The population that matters is large. TechCrunch estimates roughly 80 percent of iPhone users are still on iOS 26 two weeks after iOS 27 shipped. In managed environments that share is likely higher, because most MDM programs deliberately hold a major release for a validation cycle. That is the exact fleet Apple's warning describes.

Two groups deserve a closer look. First, anyone whose upgrade to iOS 27 or macOS 27 is blocked by app compatibility, hardware, or a policy freeze. Second, high-risk individuals: executives, journalists, lawyers, and anyone else who plausibly fits "specific targeted individuals." The CVSS 3.1 vector recorded by NVD is 8.8 with network attack vector and user interaction required, which describes opening a file. CoreGraphics renders images and PDFs across the system, including in previews and thumbnails, so several outlets note that a messaging app or mail client with automatic preview could make the interaction implicit. That is speculation; Apple has not confirmed a zero-click path.

Technical Analysis

CoreGraphics is Apple's 2D rendering framework. It parses image and PDF data on behalf of nearly every app that displays a picture, which makes it a classic file-format parser target: complex input, decades-old code, and a call path that untrusted data reaches without the user doing anything deliberate. An out-of-bounds write (CWE-787) in a parser means attacker-controlled bytes land outside the buffer they were meant for. From there an exploit author corrupts adjacent memory to hijack control flow. The mechanics of how a crafted image or PDF becomes code execution on a phone are well understood and are exactly what the "extremely sophisticated" label implies: a working chain, not a crash.

The Meta credit invites comparison with August 2025, when Meta reported an ImageIO zero-dayZero-Day🛡️A security vulnerability that is exploited or publicly disclosed before the software vendor can release a patch, giving developers 'zero days' to fix it. (CVE-2025-43300) that was chained with a WhatsApp flaw (CVE-2025-55177) in targeted attacks. SecurityWeek raised that precedent and was careful to say it is unclear whether CoreGraphics was reached through WhatsApp this time. Nothing published by either company settles it.

There is a second Apple memory bug in the news cycle that should not be confused with this one. TechCrunch and Infosecurity Magazine describe CVE-2026-86869, a zero-click iMessage flaw found by ironPeak that could bypass BlastDoor. That bug is not on CISA's list and Apple has not said it was exploited. CVE-2026-86950 is the only Apple entry added to KEV this week.

Immediate Actions

Push iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to every device that is not on a 27 release. Do not wait for the normal maintenance window; the federal deadline is three days from catalog entry and that pace is a reasonable proxy for private-sector urgency when a vendor uses the phrase "extremely sophisticated attack." Organizations that already run iOS 27 or macOS Golden Gate 27 across the fleet have nothing to do for this CVE beyond confirming that no stragglers remain on 26.x or 15.x.

For managed fleets, this is a test of whether your update tooling can enforce a point release on a branch you have not yet migrated off. How to push an emergency OS update across a managed Apple fleet is the operational question, and the answer depends on whether your MDM can target a minor update without also forcing the major upgrade. Verify installed versions from device inventory afterwards rather than trusting the push report.

Devices that cannot receive the update need a decision. Apple's supported-device floor for iOS 26 is iPhone 11; anything older is not on the fix list and Apple has published no update for earlier iOS branches as part of this release. Treat those as out of support for this CVE and reduce their exposure to untrusted files or retire them.

The KEV entry has forensic triageForensic Triage🛡️A rapid, structured assessment of whether a system was compromised, performed alongside patching rather than after it. It prioritizes evidence the attacker could not have altered, such as network egress and authentication logs on other systems, over the affected host's own logs. marked "Yes," meaning federal agencies must check for compromise, not just patch. For everyone else, the practical version is: identify who in your organization fits a targeted-individual profile, check their devices' update status first, and review whether Lockdown Mode is enabled for people who are plausibly worth an exploit chainExploit Chain🛡️Two or more vulnerabilities used in sequence so that each one supplies the access the next one requires, for example an unauthenticated SSRF that reaches a command injection which alone would need administrator credentials. Chains let attackers turn moderate individual flaws into unauthenticated remote code execution. of this cost.

Long-Term Outlook

This is the ninth Apple entry CISA has added to KEV in 2026, by our count of the feed. The Register described it as the seventh zero-day Apple has fixed this year; that figure is not verifiable from Apple's own pages and we note the disagreement. Either count puts Apple firmly in the tier of vendors whose products attract exploit development for use against individuals.

The structural lesson is about branches. Apple ships fixes to the current release and, for a period, to the previous ones. Here the current release did not need the fix at all. Every fleet that deferred the 27 upgrade was carrying a vulnerabilityVulnerability🛡️A weakness in software, hardware, or processes that can be exploited by attackers to gain unauthorized access or cause harm. that the upgrade would have removed two weeks earlier, without anyone knowing it. Why staying on last year's OS branch extends your zero-day exposure is the planning conversation this incident should trigger. The answer is not "upgrade on day one," but it is "know exactly what the deferral costs and have a fast path for point releases on the old branch."

Finally, note what Apple did not publish: no indicators, no delivery vector, no target profile. That is consistent with how Apple handles mercenary-spyware-class incidents, and it means defenders should not expect detection content for this one. Patch coverage is the only control that is fully within reach.

Sources

  • Apple, "About the security content of iOS 26.7.1 and iPadOS 26.7.1": https://support.apple.com/en-us/149226
  • Apple, "About the security content of macOS Tahoe 26.7.1": https://support.apple.com/en-us/149228
  • Apple, "About the security content of macOS Sequoia 15.8.1": https://support.apple.com/en-us/149229
  • Apple, security releases index (iOS 27 released 14 September; 27.0.1 entries with no published CVEs): https://support.apple.com/en-us/100100
  • Apple, "About the security content of iOS 27 and iPadOS 27": https://support.apple.com/en-us/149034
  • CISA, "CISA Adds One Known Exploited Vulnerability to Catalog" (29 September 2026): https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog
  • CISA KEVCISA KEV🛡️The Known Exploited Vulnerabilities catalog maintained by CISA, listing vulnerabilities actively exploited in attacks that federal agencies must patch by specific deadlines. JSON feed (dateAdded 2026-09-29, dueDate 2026-10-02, forensicTriage Yes): https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
  • NVD, CVE-2026-86950 (CVSS 3.1 8.8, CWE-787): https://nvd.nist.gov/vuln/detail/CVE-2026-86950
  • SecurityWeek, "Apple Patches Meta-Reported Zero-Day Linked to 'Extremely Sophisticated Attack'": https://www.securityweek.com/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack/
  • TechCrunch, "Still running iOS 26? Update your iPhones, iPads and Macs for this urgent security fix": https://techcrunch.com/2026/09/29/still-running-ios-26-update-your-iphones-ipads-and-macs-for-this-urgent-security-fix/
  • BleepingComputer, "Apple patches CoreGraphics zero-day flaw exploited in attacks": https://www.bleepingcomputer.com/news/security/apple-patches-coregraphics-zero-day-flaw-exploited-in-attacks/
  • The Register, "Apple patches CoreGraphics zero-day already exploited in targeted attacks": https://www.theregister.com/security/2026/09/29/apple-patches-coregraphics-zero-day-already-exploited-in-targeted-attacks/5299721
  • Help Net Security, "Apple squashes zero-day bug exploited in 'extremely sophisticated' attack": https://www.helpnetsecurity.com/2026/09/29/apple-core-graphics-zero-day-cve-2026-86950-fixed/
  • Infosecurity Magazine, "Apple Patches CoreGraphics Zero Day Exploited in Attacks": https://www.infosecurity-magazine.com/news/apple-patches-coregraphics-zero/
  • The Hacker News, "Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks": https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html