Particle.news
Download on the App Store

Apple Issues Emergency Patch for CoreGraphics Zero-Day

Fixing the bug reduces the risk that attackers could run code from crafted images or PDFs on older Apple devices.

Overview

  • Apple released fixes on Monday, Sept. 28 in iOS and iPadOS 26.7.1 and in macOS Tahoe 26.7.1 and Sequoia 15.8.1 to close the vulnerability.
  • The flaw is an out-of-bounds write in CoreGraphics that can let processing a maliciously crafted file corrupt memory or allow arbitrary code execution.
  • Meta Product Security reported the bug and Apple said it may have been used in an 'extremely sophisticated' targeted attack but did not name victims or explain how the malicious files were delivered.
  • The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog on Sept. 30 and ordered federal agencies to remediate the issue by Oct. 2, 2026.
  • Security firms warned the bug raises special concerns for high-value targets and cryptocurrency users because a compromised device can expose wallet secrets, but there is no public proof the flaw directly caused wallet thefts and users should update affected devices now.