537/69 Wednesday, September 30, 2026

Apple has released security updates to address CVE-2026-86950, an out-of-bounds write vulnerability in the CoreGraphics component. Processing a specially crafted file could lead to code execution on an affected device. Apple stated that it received a report indicating the vulnerability may have been exploited in an extremely sophisticated attack against specifically targeted users running versions of iOS earlier than iOS 27. However, Apple has not disclosed additional information about the attackers, targets, or attack vector.
The vulnerability is caused by an out-of-bounds memory write in CoreGraphics when the system processes a specially crafted file, potentially allowing an attacker to execute unauthorized code. Apple addressed the issue by improving bounds checking. There is currently no confirmed information indicating that the vulnerability was exploited through WhatsApp or that it can be used in a zero-click attack. Therefore, the exact attack method cannot yet be determined from the information currently available.
Apple has fixed CVE-2026-86950 in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Users should check their devices and update to the fixed versions or later as soon as possible, particularly devices running versions of iOS earlier than iOS 27, which Apple stated may have been targeted through exploitation of this vulnerability.
