2026-09-30HIGHexploitedApple patches a CoreGraphics zero-day exploited against targeted iPhone users; a crafted file can lead to code execution
Apple iOS/iPadOS/macOS CoreGraphics out-of-bounds write exploited in a targeted attack on iOS before iOS 27, fixed in 26.7.1 / Tahoe 26.7.1 / Sequoia 15.8.1, CISA KEV 2026-09-29
cve · CVE-2026-86950
Coverage
1
first 2026-09-30 → last 2026-09-30
Latest activity
2026-09-30
Apple patches a CoreGraphics zero-day exploited against targeted iPhone users; a crafted file can lead to…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector
Sources cited
7
5 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2026-86950, newest first. Check the date before acting on an older one.
- Push iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 through device management now, starting with the devices of staff who could be individually targeted; Apple describes the exploitation only on iOS before iOS 27.2026-09-30CVE-2026-86950
Defender insights
What each entry about CVE-2026-86950 tells a defender to do, newest first.
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionExploitation for Client Execution
Execution TA0002
T1203Exploitation for Client Execution×1
Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior. Adversaries can take advantage of certain vulnerabilities through targeted exploitation for the purpose of arbitrary code execution. Oftentimes the most valuable exploits to an offensive toolkit are those that can be used to obtain code execution on a remote system because they can be used to gain access to that system. Users will expect to see files related to the applications they commonly used to do work, so they are a useful target for exploit research and development because of their high utility.
Evidence: 2026-09-30/cve-2026-86950-apple-coregraphics-zero-day-kev · ATT&CK page ↗
Entries about Apple iOS/iPadOS/macOS CoreGraphics out-of-bounds write exploited in a targeted attack on iOS before iOS 27, fixed in 26.7.1 / Tahoe 26.7.1 / Sequoia 15.8.1, CISA KEV 2026-09-29 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- support.apple.com3 (43%)
- cisa.gov1 (14%)
- euvd.enisa.europa.eu1 (14%)
- securityweek.com1 (14%)
- thehackernews.com1 (14%)
External references
All cited sources (7)
- support.apple.comprimaryApple Security (iOS 26.7.1 and iPadOS 26.7.1)https://support.apple.com/en-us/149226
- support.apple.comprimaryApple Security (macOS Tahoe 26.7.1)https://support.apple.com/en-us/149228
- support.apple.comprimaryApple Security (macOS Sequoia 15.8.1)https://support.apple.com/en-us/149229
- cisa.govCISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- euvd.enisa.europa.euENISA EU Vulnerability Databasehttps://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88445
- securityweek.comSecurityWeekhttps://www.securityweek.com/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack/
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html