Security1 publisher2 min readPublished
Apple patches CoreGraphics bug that may have been used in targeted iPhone attacks
Apple patched CoreGraphics flaw CVE-2026-86950 in iOS 26.7.1 after a report that it may have been exploited against targeted iPhone users. iPhone fleets still on iOS 26 have the strongest case for forcing that update before the next scheduled patch window.
The Watch · Security desk

What happened
- The same fix ships in iPadOS 26.7.1 and in two Mac releases, macOS Sequoia 15.8.1 and macOS Tahoe 26.7.1.
- CVE-2026-86950 is an out-of-bounds write in CoreGraphics, the framework Apple's systems and apps use to display and process images and PDFs.
- If an unpatched device processes a maliciously crafted file, the attacker may be able to run their own code in the affected process.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability Any app that hands an image or PDF to CoreGraphics is a possible route for the crafted file, so filtering one channel such as email attachments leaves the others open.
- exposure Malwarebytes says other attackers could try the flaw now that it is public. Unpatched devices now face more attackers than the one behind the original targeted operation.
- decision Macs on Sequoia and Tahoe need 15.8.1 or 26.7.1, but the reported attack involved iOS only, so Macs can come after iPhones on iOS 26 in the rollout order.
An out-of-bounds write happens when software puts data past the end of the memory it was allocated [6]. The stray data can overwrite whatever sits next to it or crash the program. It can also give an attacker control of the process doing the writing [6]. For CVE-2026-86950, that is the process handling the crafted file [6]. Apple fixed it with improved bounds checking [5].
The CVE number, the framework, the bug class and the fixed builds are all public [4][5][3]. The claim of exploitation is second-hand and hedged. Apple said it is aware of a report that the issue may have been exploited in an "extremely sophisticated attack" against specific people using versions of iOS before iOS 27 [7]. The Malwarebytes account does not name the attacker, the targets or how the file reached them, so on this evidence the activity cannot be tied to a known campaign [7].
The iOS 27 cutoff tells a fleet team which phones to push first. Any iPhone on an iOS 26 build below 26.7.1 falls inside the version range the report describes and does not have the fix [1]. Devices already on iOS 27 are outside that range [7]. The range comes from an attack report, so it sets priority. It is not a vulnerability assessment of iOS 27. iPads on iPadOS 26 take the same 26.7.1 build [3], though the report as Malwarebytes relays it concerns iPhone users [2].
What to watch
- An actor or delivery route for the reported attack, named by Apple or researchers; that would place CVE-2026-86950 inside a known campaign.
- Any Apple statement on whether iOS 27 builds carry the CoreGraphics bug or need their own fix.
- Reports of CVE-2026-86950 exploitation beyond the original targets, the spread Malwarebytes says disclosure makes possible.