Apple patches a CoreGraphics zero-day, reported by Meta, that was used in targeted iOS attacks
A maliciously crafted file can lead to code execution. The fixes cover iOS, iPadOS and macOS versions older than 27.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
On Monday, Apple released iOS, iPadOS and macOS updates for an actively exploited zero-day vulnerability in CoreGraphics, the framework that handles 2D drawing, image rendering and PDF parsing. SecurityWeek and Help Net Security track the flaw as CVE-2026-86950, while BleepingComputer's report gives a different identifier. It is an out-of-bounds write that can allow arbitrary code execution when a device processes a maliciously crafted file. Apple said it is aware of a report that the issue may have been exploited 'in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.' Apple credited Meta's product security team with finding the bug and did not describe the attacks or who was targeted. SecurityWeek notes that because CoreGraphics renders content across the operating system, a malicious file could arrive through web pages, email or messaging previews. The fixes ship in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Affected devices include the iPhone 11 and later and a wide range of iPads. Help Net Security reports that iOS 27.0.1 and macOS Golden Gate 27.0.1 do not appear to be affected, but advises all users to update.