It was discovered that attackers were using certain real cyberattacks by exploiting a critical vulnerability on Apple iPhone and iPad devices!
Apple addressed the digital zero-day vulnerability with ID CVE-2026-86950, which was identified in the CoreGraphics system component. According to Apple's information, this vulnerability may have been used in sophisticated and targeted attacks against some users who were using versions prior to iOS 27.
To fix the vulnerability, Apple released security updates for iPhone and iPad devices, including iOS 26.7.1 and iPadOS 26.7.1, on September 28, 2026. Additionally, this issue was also fixed on Mac computers, with security patches released for macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 versions.
What is the zero-day vulnerability dangerous?
CVE-2026-86950 is a bug related to an "out-of-bounds write" in the CoreGraphics component, which means it allows writing data outside the allocated memory space of a program.
CoreGraphics is one of the important system components used in Apple operating systems for processing graphics, images, and documents. Therefore, this vulnerability can pose a more serious risk than a simple software error.
According to Apple's information, this vulnerability could be exploited during the processing of specially crafted malicious files, potentially allowing an attacker to execute arbitrary code on the device.
In other words, if a user works with a maliciously crafted file—such as opening, viewing, or the system processing it—there is a possibility that the vulnerable component can be triggered.
If such an attack is successful, the attacker may gain the ability to run the code they need on the device, carry out subsequent attack stages, or access other confidential information. The exact outcome depends on how the attack was orchestrated and whether other vulnerabilities were exploited or not.
Was the vulnerability used in real attacks?
Apple provided very important information in its security bulletin regarding CVE-2026-86950, stating that it was aware that this vulnerability might have been used in very complex attacks against some specifically targeted individuals using versions prior to iOS 27.
However, Apple has not disclosed the exact details of the attacks, how many users were targeted, when the attacks started, or how many were successfully concluded. Furthermore, the company has not specified whether this vulnerability was used in conjunction with other zero-day vulnerabilities.
Therefore, it is not accurate to conclude that this situation "is actively being exploited in a wide range of vulnerabilities." Currently, the available official information only indicates that it may have been used in some targeted attacks.
How did Apple fix the vulnerability?
Apple fixed the issue by enhancing the memory boundary checking mechanism. This change helps prevent data from being written outside the allocated memory space of the program.
The vulnerability was identified by Meta Product Security and reported to Apple. Apple then announced the relevant security updates on September 28, 2026.
Which devices are at risk?
According to Apple's information, iOS 26.7.1 and iPadOS 26.7.1 were released for the following devices:
- iPhone 11 and later models;
- iPad Pro 12.9-inch — 3rd generation and later models;
- iPad Pro 11-inch — 1st generation and later models;
- iPad Air — 3rd generation and later models;
- iPad — 8th generation and later models;
- iPad mini — 5th generation and later models.
In addition, Apple also included the fix related to CVE-2026-86950 in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 versions.
What should users do?
It is recommended that users of Apple devices install the security updates as soon as possible.
To do this:
Go to the Settings → General → Software Update section to check and install the available update.
It is important for users who work with confidential information, use email, messengers, corporate systems, and other important resources during their work to check the software version on their devices.
In organizations, it is recommended to monitor the updated or unupdated status of Apple devices through MDM (Mobile Device Management) systems, identify devices that are on older versions, and install security updates on them.
Why should we pay special attention to zero-day vulnerabilities?
The danger of zero-day vulnerabilities is that attackers can use them before an official patch is released or while the patch is not yet widely installed.
In the case of CVE-2026-86950, the problem is even more serious: information was received that this vulnerability might have been used in very complex attacks against some specifically targeted individuals.
This situation highlights the importance of regularly updating operating systems and applications, being cautious when opening files from unknown sources, and managing devices centrally.
CVE-2026-86950 is a critical memory security vulnerability in the CoreGraphics component on Apple devices, which can lead to arbitrary code execution during the processing of specially crafted files. Information was obtained that this vulnerability might have been used in very complex attacks against some targeted devices with versions prior to iOS 27.
Therefore, it is recommended to install the relevant security updates for iPhone, iPad, and Mac users without delay. Delaying the update leaves the device unprotected against a known vulnerability.
