Signal is active with 45 mentions in latest observed window
Immediate actions
Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-10-02. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
‼️ Apple patched a new CoreGraphics flaw that may have been exploited in targeted iOS attacks.
CVE-2026-86950 can trigger arbitrary code execution when a maliciously crafted file is processed. Fixes are available for affected older iOS, iPadOS, and macOS releases.
Read: https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html
🚨 Apple has released an important security update for iOS/iPadOS 26.7.1, addressing CVE-2026-86950, an out-of-bounds write vulnerability that may lead to arbitrary code execution.
As we previously reported, this update is highly relevant to the iOS attack activity we have been tracking. Apple confirmed that the vulnerability may have been exploited in highly sophisticated attacks targeting specific individuals on iOS versions before iOS 27.
For crypto users, this is especially concerning given the iOS exploitation activity we have observed targeting sensitive wallet data.
🔐 Please:
• Update your iPhone, iPad, Mac and other Apple devices to the latest available security updates.
• Avoid installing apps from unknown or untrusted sources.
• Do not open suspicious links in Safari or in-app browsers.
• Treat unexpected files, links and app installation prompts with caution.
Stay alert and keep your devices updated.
Apple Security Update: https://support.apple.com/en-us/149226
📣 EMERGENCY UPDATE 📣
Apple pushed updates for a new zero-day that may have been actively exploited.
🐛 CVE-2026-86950 (CoreGraphics):
- iOS and iPadOS 26.7.1
- macOS Sequoia 15.8.1
- macOS Tahoe 26.7.1
🍎 🚨 APPLE PATCHES COREGRAPHICS FLAW THAT MAY HAVE BEEN EXPLOITED IN TARGETED ATTACKS
Apple has released security updates for older iOS, iPadOS, and macOS versions addressing CVE-2026-86950, an out-of-bounds write in CoreGraphics that can lead to arbitrary code execution when processing a maliciously crafted file.
Key points from Apple:
• Impact: processing a crafted file may lead to arbitrary code execution
• Fix: improved bounds checking
• Credited: Meta Product Security
• Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27
• No public detail yet on volume of targets, success, or first exploitation date
Patched in:
• iOS 26.7.1 and iPadOS 26.7.1
• macOS Tahoe 26.7.1
• macOS Sequoia 15.8.1
⚠️ Analyst Note:
Apple’s wording indicates possible targeted exploitation on pre–iOS 27 builds, not confirmed mass exploitation. Treat this as a high-priority patch advisory: update eligible devices promptly, and do not overstate the attack as a broad consumer campaign without further evidence.
Sources (Apple Support):
https://support.apple.com/en-us/149226
https://support.apple.com/en-us/149228
https://support.apple.com/en-us/149229
#Apple#iOS#macOS#CVE#CoreGraphics#ZeroDay#ThreatIntel#CyberSecurity#DDW
iOS 26.7.1 and iPadOS 26.7.1 fixes - CVE-2026-86950: Meta Product Security
Impact: Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.
Description: An out-of-bounds write issue was addressed with improved bounds checking.
Apple patched CVE-2026-86950, a CoreGraphics zero-day on iOS and macOS that may have enabled code execution in highly targeted attacks. Meta's security team reported the issue. #Apple#CoreGraphics#Meta
https://www.hendryadrian.com/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack/
Apple patched a CoreGraphics zero-day (CVE-2026-86950) reported by Meta, warning the flaw was targeted in extremely sophisticated attacks. https://www.securityweek.com/apple-patches-meta-reported-zero-day-linked-to-extremely-sophisticated-attack/
Learn about the critical CVE-2026-86950 zero-day vulnerability patched in iOS 26.7.1. Discover how this CoreGraphics flaw could lead to malicious code execution.
#AppleSecurity#iOSUpdate#ZeroDay#CyberSecurity#TechNews
https://securityexpress.info/apple-patches-zero-day-ios-26-7-1/
🚨 Apple patched CVE-2026-86950, a CoreGraphics flaw that can lead to arbitrary code execution through a maliciously crafted file.
Apple says it may have been exploited in a highly targeted attack.
No public exploit known.
🔎 https://exploitgrid.net/vulnerabilities/CVE-2026-86950
🚨 Apple corrige una falla de seguridad en iPhone
iOS 26.7.1 y iPadOS 26.7.1 parchean CVE-2026-86950, que podía permitir ejecutar código tras procesar un archivo manipulado.
Apple reportó posible explotación en ataques dirigidos.
SlowMist alerta a usuarios cripto, pero no confirmó que la falla causara robos de billeteras.
Actualiza tu dispositivo.
Patch Now | September 29, 2026
Bringing these vulnerabilities to your attention:
- Citrix NetScaler: two zero-days (CVE-2026-88771, CVE-2026-88772)
- Apple CoreGraphics (CVE-2026-86950)
- F5 BIG-IP APM (CVE-2026-94127)
https://cert.ug | #CyberSafeUG#CERTUGCC https://t.co/KmgcRDvkDe
Other side.
Targeted + “extremely sophisticated” is how Apple usually talks when the buyer is a spy shop and the set is small. Most people on iOS 26 are not that set.
Once the CVE is public, opportunistic copycats become a separate problem. Unpatched 26.x / Tahoe / Sequoia is the exposed set now, even if you were never in the original targeting.
CISA KEV, checked this morning: CVE-2026-86950 is not in the adds I can see. NetScaler 88771/88772 from 27 Sep are. Absence of KEV is not absence of risk. It is absence of CISA’s listing.
Also: at least one writeup mixed this bug with CVE-2026-20700, a February dyld memory-corruption issue. Different component, different month. Flattening CVE numbers is how bad threads get born.