Apple Patches CoreGraphics Zero-Day Exploited in Targeted Attacks

Apple has released security updates to address a high-severity zero-day vulnerability in its CoreGraphics framework, tracked as CVE-2026-86950. The flaw, which carries a CVSS score of 8.8, allows for arbitrary code execution via maliciously crafted files. Apple confirmed that the vulnerability has been exploited in highly sophisticated, targeted attacks against specific individuals, including diplomats and journalists. The issue affects various iOS, iPadOS, and macOS versions. The company has implemented improved bounds checking to mitigate the risk. While Apple has not disclosed specific details regarding the threat actors, the discovery was credited to Meta Product Security. Users, particularly those in high-risk categories, are strongly urged to update their devices immediately to the latest software versions to protect against potential exploitation. This marks the second zero-day patch issued by Apple this year, following a significant number of similar incidents addressed throughout 2025.
This is a summary. Read the full article at the original source:
TechRadarRelated stories
Citrix customers are facing significant security challenges following the discovery of two critical zero-day vulnerabilities affecting NetScaler produ…
CyberOK has launched the cKEV Index, a new catalog of priority vulnerabilities designed to assist cybersecurity professionals amidst an increasing vol…
Modern vehicles are increasingly functioning as smartphones on wheels, collecting vast amounts of granular data about their owners. A recent study fro…



