Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CoreGraphics Vulnerability in Apple Devices Exploited in Sophisticated Targeted Attacks


Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS, which it believes may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, could have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

  • Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS, CVE-2026-86950.
  • The vulnerability could have been exploited in targeted attacks against specific individuals on older iOS versions.
  • The update is available for devices and operating system versions from iOS 26.7.1 to macOS Sequoia 15.8.1.
  • The disclosure highlights the ongoing cat-and-mouse game between device manufacturers and hackers.
  • Device users should remain vigilant and keep their devices up to date with the latest security patches.



  • Apple has recently released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS, which it believes may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. This issue was first reported by Meta Product Security, which discovered and reported the issue to Apple.

    According to Apple, the vulnerability could have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. However, the company has offered no further details on the number of individuals affected, whether any attempts were successful, or when the first instance of CVE-2026-86950 exploitation occurred. This lack of information has led some to speculate that the company is being cautious in its disclosure, potentially to avoid raising unnecessary alarms or to prevent potential attackers from spreading misinformation.

    The vulnerability was addressed in the following devices and operating system versions: iOS 26.7.1 and iPadOS 26.7.1, iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later, and macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.

    This is not the first time that Apple has addressed a vulnerability in its devices. Earlier this February, the company released security updates to address a memory corruption issue in the dyld component, which it said had been weaponized in sophisticated cyber attacks. The vulnerability, tracked as CVE-2026-20700, had a CVSS score of 7.8, indicating a high level of severity. The issue was addressed with improved bounds checking, and the company credited Meta Product Security with discovering and reporting the issue.

    The disclosure of this vulnerability highlights the ongoing cat-and-mouse game between device manufacturers and hackers. As devices become more complex and interconnected, the potential for vulnerabilities to be discovered and exploited increases. It is a sobering reminder for device users to remain vigilant and to keep their devices up to date with the latest security patches.

    In recent years, there have been numerous high-profile incidents of vulnerabilities being exploited in targeted attacks. In 2020, for example, the COVID-19 pandemic led to an increase in attacks on healthcare organizations, with hackers exploiting vulnerabilities in devices and systems to gain unauthorized access. Similarly, in 2022, the attack on Colonial Pipeline, a major US fuel pipeline, highlighted the risks of vulnerability exploitation in critical infrastructure.

    The exploitation of vulnerabilities in devices and systems is a growing concern, with hackers using increasingly sophisticated techniques to gain unauthorized access. As the use of artificial intelligence and machine learning becomes more widespread, the potential for vulnerabilities to be exploited also increases. It is essential that device manufacturers and organizations prioritize security and take proactive steps to address vulnerabilities before they can be exploited.

    In conclusion, the disclosure of the CoreGraphics vulnerability in Apple devices highlights the ongoing risks of vulnerability exploitation. As device users, it is essential to remain vigilant and to keep our devices up to date with the latest security patches. By working together, we can reduce the risk of vulnerabilities being exploited and create a safer digital landscape.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CoreGraphics-Vulnerability-in-Apple-Devices-Exploited-in-Sophisticated-Targeted-Attacks-ehn.shtml

  • https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html


  • Published: Mon Sep 28 15:56:28 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us