APPLE FIXES COREGRAPHICS FLAW USED IN TARGETED ATTACKS
Apple has released a fix for a security vulnerability in CoreGraphics, its graphics framework used across iPhone, iPad and Mac devices, after saying the flaw may have been exploited in what it called an extremely sophisticated attack against specific targeted individuals. The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write issue that could let an attacker execute arbitrary code on a device by getting it to process a maliciously crafted file, according to Apple's advisory. The fix was released on Monday in iOS 26.7.1 and iPadOS 26.7.1, along with macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1. Meta's Product Security team reported the flaw to Apple. The National Vulnerability Database rated the bug 8.8 out of 10 for severity, describing it as high-risk.
Apple said the issue affected versions of iOS before iOS 27 and did not disclose who was targeted, how many people were affected, or who carried out the attacks. Neither Apple nor Meta has released further technical detail on how the vulnerability was discovered or how it was used in the field. Affected devices include the iPhone 11 and later, and the iPad Pro 12.9-inch 3rd generation and later. CoreGraphics handles the drawing and rendering of visual elements such as lines, shapes, text and colour across Apple's operating systems, giving the bug broad reach across the company's product line.
Apple has urged all users to install the latest security updates without delay, and said the update is particularly important for people who may be at higher risk of targeted surveillance, including diplomats, dissidents, whistleblowers, political opposition figures and journalists. The company's limited disclosure is consistent with its usual approach to vulnerabilities that have already been exploited, when it typically withholds detail to avoid aiding further attacks. No further updates on the investigation have been announced.