Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Executive Summary

Apple released security updates for older iOS, iPadOS, and macOS versions to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics that could allow arbitrary code execution via malicious files. The flaw may have been used in targeted attacks.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-28T19:18:01+00:00 - Category: vulnerabilities

Original Description: Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the

"Keep yourself to the sunshine and you cannot see the shadow."

— Helen Keller
Source: The Hacker News