The Register·3 min read·hard

Apple patches CoreGraphics zero-day already exploited in targeted attacks

C
Carly Page
Apple patches CoreGraphics zero-day already exploited in targeted attacks
✦AI Summary

Apple has released a security patch for a zero-day vulnerability in its CoreGraphics framework that was exploited in targeted attacks. The flaw allowed for arbitrary code execution, prompting Apple to improve bounds checking in its latest iOS and iPadOS updates.

Why it matters

The exploitation of zero-day vulnerabilities in Apple products highlights the ongoing risks posed by sophisticated spyware campaigns against high-value targets.

✦Dive DeeperCreate a free account to unlock

Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file

Apple has patched a CoreGraphics zero-day after warning that attackers may already have used the bug to compromise a small number of carefully chosen targets.

The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write flaw in CoreGraphics, Apple's framework for handling graphics across its operating systems.

According to Apple's advisory, processing a maliciously crafted file could allow an attacker to execute arbitrary code on a vulnerable device. The fruity vendor said it addressed the problem with improved bounds checking, though the bug appears to have made it out into the wild before Apple could squash it.

"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27," the company said.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyscience
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in