What is CoreGraphics?
CoreGraphics, historically called Quartz 2D, is the low-level drawing engine underneath almost everything visible on an Apple device. It handles path-based drawing, coordinate transformations, color management, offscreen rendering, patterns and gradients, and it decodes and rasterizes image and PDF data on behalf of higher-level frameworks. Every app that shows a photo, renders a PDF preview, or draws text ends up inside CoreGraphics code.
That ubiquity is what makes it valuable to an attacker. CoreGraphics parsing is reached without the user doing anything deliberate: a message attachment thumbnail, a web page image, a document preview in Quick Look or Mail. Parsers that run automatically on untrusted input, in a framework shared by every process on the system, are the classic starting point for a remote exploit chain, which is why Apple's image and font parsing code has produced repeated in-the-wild zero-days.
Overview
CVE-2026-86950 is an out-of-bounds write in CoreGraphics. Apple's advisory language is terse and consistent across platforms: "Processing a maliciously crafted file may lead to arbitrary code execution." The company fixed it with improved bounds checking and shipped the patch on 2026-09-28 in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.
Apple attached its standard exploitation notice: it is "aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." That phrasing is the wording Apple reserves for mercenary spyware and state-aligned intrusion activity rather than commodity malware. The iOS 27 line already contains the fix, so these releases are a backport for the large installed base still on the 26.x and Sequoia branches.
CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2026-09-29, one day after the patch, with a remediation deadline of 2026-10-02. The three-day window is unusually tight and reflects both the confirmed exploitation and the fact that a vendor patch is already available.
Affected Versions
| Product | Vulnerable | Fixed |
|---|---|---|
| iOS (iPhone 11 and later) | Before 26.7.1 | 26.7.1 |
| iPadOS (iPad Pro 12.9-inch 3rd gen and later, iPad Pro 11-inch 1st gen and later, iPad Air 3rd gen and later, iPad 8th gen and later, iPad mini 5th gen and later) | Before 26.7.1 | 26.7.1 |
| macOS Tahoe | Before 26.7.1 | 26.7.1 |
| macOS Sequoia | Before 15.8.1 | 15.8.1 |
| iOS / iPadOS 27 | Not affected | Not applicable |
Technical Details
The weakness is CWE-787, an out-of-bounds write. In plain terms, CoreGraphics allocates a buffer sized from one part of a file and then writes into it using a length or offset taken from another part, without checking that the write stays inside the allocation. A crafted file drives that write past the end of the buffer and corrupts whatever memory sits next to it. Attacker-controlled corruption of adjacent heap objects is the standard route to hijacking a function pointer or object vtable and redirecting execution.
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, base score 8.8. Network vector, no privileges, low complexity, but user interaction required: something has to hand the malicious file to the framework. In practice that bar is low, since preview generation and automatic image rendering count.
Apple has published no detail on the file format involved, the specific parser, or which process the exploit lands in. Neither Apple nor Meta has released technical analysis, and no proof-of-concept is public. On its own an out-of-bounds write in a sandboxed rendering process is not a full compromise, so a working intrusion almost certainly chained this with a sandbox escape and a kernel privilege escalation; no such companion CVEs have been named.
Discovery
Apple credits Meta Product Security in all three advisories. Meta has not published a write-up, and neither party has said how the bug surfaced, whether through proactive review, telemetry from Meta's own messaging platforms, or victim device analysis. Reporting organizations that find a bug already under active exploitation typically find it in the second way, and Apple's wording, a report that the issue "may have been exploited," is consistent with attribution arriving alongside the bug report rather than from Apple's own detection.
Exploitation Context
Apple confirms targeted exploitation and says nothing further. There is no named threat actor, no victim count, no campaign name, no targeted sector, and no delivery vector confirmed by any source. CISA does not flag the CVE as used in ransomware campaigns. Exposure counts of the kind published for server-side flaws do not apply here, since the affected population is every unpatched Apple client device.
Sources disagree on how many exploited zero-days Apple has patched in 2026: BleepingComputer counts this as the second, while The Register calls it the seventh. The discrepancy is most likely a difference in what each counts, and the number should not be treated as settled. The clearer comparison point is CVE-2026-20700, a dyad memory corruption flaw Apple patched in February 2026 that was likewise described as used in sophisticated attacks.
The practical reading for defenders: exploitation is real but narrow today. The risk profile changes once the patch is diffed, because a fix described as "improved bounds checking" tends to make the vulnerable path obvious to anyone comparing binaries.
Remediation
- Update to iOS 26.7.1 or iPadOS 26.7.1 on mobile devices, macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1 on Macs. Devices already on iOS or iPadOS 27 need no action for this CVE.
- Push the update through MDM rather than relying on user-initiated installs, and confirm compliance by build number. Federal civilian agencies were required to remediate by 2026-10-02 under BOD 26-04.
- Enable automatic updates on any device outside MDM management, including personally owned devices under a BYOD program.
- For individuals plausibly in scope for targeted attacks, journalists, activists, executives, government staff, turn on Lockdown Mode. It disables or restricts much of the automatic file and image handling that a CoreGraphics exploit needs to reach its parser.
- There is no vendor workaround and no configuration change that mitigates this short of patching. Network controls do not help, because the malicious file arrives over whatever channel the user already uses.
- For suspected targets, check Apple threat notifications on the Apple ID account, review the device for unexpected profiles, configuration changes or unfamiliar apps, and preserve a sysdiagnose before wiping. Escalate to a forensics team rather than triaging in place, since a full reset destroys the evidence of what happened.
- Watch for follow-up reporting. If Meta or a research group publishes the chain this was part of, the companion sandbox escape and kernel bugs will matter as much as this one.
Key Details
| Property | Value |
|---|---|
| CVE ID | CVE-2026-86950 |
| Vendor / Product | Apple — Multiple Products |
| NVD Published | 2026-09-28 |
| NVD Last Modified | 2026-09-29 |
| CVSS 3.1 Score | 8.8 |
| CVSS 3.1 Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Severity | HIGH |
| CWE | CWE-787 find similar ↗ |
| CISA KEV Added | 2026-09-29 |
| CISA KEV Deadline | 2026-10-02 |
| Known Ransomware Use | No |
CVSS 3.1 Breakdown
Required Action
Timeline
| Date | Event |
|---|---|
| 2026-09-28 | Apple ships iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, crediting Meta Product Security |
| 2026-09-28 | CVE-2026-86950 published |
| 2026-09-29 | Added to CISA Known Exploited Vulnerabilities catalog |
| 2026-10-02 | CISA BOD 26-04 remediation deadline |