Apple Fixes Exploited Zero-Day in Older iOS, iPadOS, and macOS Versions

Apple has released security updates for older versions of iOS, iPadOS, and macOS to address a vulnerability that may have been exploited in targeted attacks.

The vulnerability, tracked as CVE-2026-86950, affects the CoreGraphics component and could allow arbitrary code execution when the system processes a maliciously crafted file.

Apple said the vulnerability was fixed through improved bounds checking.

CVE-2026-86950 Details

CVE-2026-86950 is an out-of-bounds write vulnerability in CoreGraphics.

An attacker could potentially exploit the flaw by convincing a targeted user or device to process a specially crafted file, resulting in arbitrary code execution.

Apple credited Meta Product Security with discovering and reporting the vulnerability.

The company also said it is aware of a report indicating that the vulnerability may have been exploited in an extremely sophisticated attack against specific individuals running versions of iOS before iOS 27.

Apple has not disclosed:

  • The number of targeted individuals
  • Whether the attacks were successful
  • When exploitation first began
  • The identity of the attackers
  • The exact attack chain used in the reported incidents

Affected Apple Platforms

Apple has addressed the vulnerability in the following updates:

PlatformFixed VersioniOS26.7.1iPadOS26.7.1macOS Tahoe26.7.1macOS Sequoia15.8.1

The iOS and iPadOS updates apply to supported devices including:

  • iPhone 11 and later
  • iPad Pro 12.9-inch 3rd generation and later
  • iPad Pro 11-inch 1st generation and later
  • iPad Air 3rd generation and later
  • iPad 8th generation and later
  • iPad mini 5th generation and later

Apple Warns of Targeted Exploitation

Apple's advisory specifically notes that the vulnerability may have been used in an attack against a limited group of targeted individuals.

The company described the reported activity as an extremely sophisticated attack, but did not provide technical details about the exploitation process.

Because Apple has confirmed potential exploitation, users running affected versions should install the applicable security update as soon as possible.

Previous Apple Zero-Day

This is not the first exploited Apple vulnerability disclosed in 2026.

Earlier this year, Apple patched CVE-2026-20700, a memory corruption vulnerability in the dyld component. Apple said that flaw had also been weaponized in sophisticated cyberattacks.

Key Takeaway

CVE-2026-86950 is an actively relevant Apple security issue because the company has acknowledged reports of potential exploitation in targeted attacks.

Users running affected versions of iOS, iPadOS, or macOS should update to the latest supported security release to reduce exposure to attacks involving maliciously crafted files.