CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8765

As cited

Copy frozen at (site build).

vulnerabilities

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Apple released security updates to address CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics affecting iOS, iPadOS, and macOS. The flaw could enable remote code execution through a malicious file and may have been exploited in targeted attacks.

Why it matters: Users of older iOS, iPadOS, and macOS versions should prioritize patching to remediate potential active exploitation in targeted campaigns.

VendorsApple
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Apple released security updates to address CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics affecting iOS, iPadOS, and macOS. The flaw may have been exploited in targeted attacks and could allow arbitrary code execution when processing a malicious file.

Why it matters: Organizations managing Apple devices should prioritize patching iOS, iPadOS, and macOS systems to address this potentially exploited vulnerability.

VendorsApple
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Apple released security updates addressing CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics affecting iOS, iPadOS, and macOS that could enable arbitrary code execution. The flaw may have been exploited in targeted attacks.

Why it matters: Users of older iOS, iPadOS, and macOS versions should apply these updates promptly, especially those at risk of targeted attacks, to prevent potential code execution via maliciously crafted files.

VendorsApple
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary