Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Exploited by Design: The CoreGraphics Zero-Day Vulnerability and Apple's Swift Response


Apple has patched a CoreGraphics zero-day vulnerability that was reportedly exploited in targeted attacks against specific individuals running older versions of iOS. The vulnerability, which allows an attacker to execute arbitrary code on a vulnerable device, was patched in iOS 26.7.1 and iPadOS 26.7.1. The incident highlights the growing concern about the increasing number of vulnerabilities being exploited in the wild and the need for technology companies to stay ahead of the threats.

  • Apple has patched a CoreGraphics zero-day vulnerability, CVE-2026-86950, reportedly exploited in targeted attacks on older iOS versions.
  • The vulnerability allows an attacker to execute arbitrary code on a vulnerable device by processing a maliciously crafted file.
  • The affected devices receiving the update are iPhone 11 and later, as well as various iPad models.
  • This is the seventh zero-day fixed by Apple this year, highlighting the growing concern about exploited vulnerabilities.
  • The incident underscores the importance of swift patching, keeping software up to date, and protecting against targeted attacks.



  • Apple has announced a patch for a previously disclosed CoreGraphics zero-day vulnerability, CVE-2026-86950, which was reportedly exploited in targeted attacks against specific individuals running older versions of iOS. The vulnerability, an out-of-bounds write flaw in Apple's graphics framework, allows an attacker to execute arbitrary code on a vulnerable device by processing a maliciously crafted file.

    According to Apple's advisory, the issue was reported to the company by Meta Product Security, but neither Apple nor Meta has provided further technical details on how the flaw was discovered or the attacks in which it was allegedly used. The company's decision to patch the vulnerability quickly suggests that it was not a bug being exploited indiscriminately across the internet, and raises the possibility that it was used as part of a targeted spyware campaign.

    The affected devices receiving the update are the iPhone 11 and later, iPad Pro 12.9-inch (third generation and later), iPad Pro 11-inch (first generation and later), iPad Air (third generation and later), iPad (eighth generation and later), and iPad mini (fifth generation and later). However, Apple has not specified which older releases were targeted by the attacks.

    This latest patch is the seventh zero-day fixed by Apple this year, underscoring the growing concern about the increasing number of vulnerabilities being exploited in the wild before users have a chance to patch their devices. The incident highlights the importance of keeping software up to date and the need for users to be vigilant in protecting themselves against targeted attacks.

    In a broader context, the CoreGraphics vulnerability is the latest example of a previously disclosed bug being exploited by attackers. This trend is concerning, as it suggests that attackers are taking advantage of known vulnerabilities to carry out sophisticated attacks. The incident also underscores the importance of swift patching and the need for users to stay informed about the latest security updates.

    The incident also raises questions about the responsibility of technology companies to disclose vulnerabilities and to ensure that their products are secure. In this case, Meta reported the vulnerability to Apple, but the company's decision to patch it quickly suggests that it may have been unclear or ambiguous about the level of detail it was willing to provide.

    Furthermore, the incident highlights the increasing sophistication of cyber-attacks and the need for technology companies to stay ahead of the threats. The use of targeted attacks and spyware is a growing concern, and the incident underscores the importance of robust security measures to protect against such threats.

    In conclusion, the CoreGraphics zero-day vulnerability and Apple's swift response to patch it serve as a reminder of the importance of staying informed about the latest security updates and taking swift action to protect ourselves against targeted attacks. The incident highlights the growing concern about the increasing number of vulnerabilities being exploited in the wild and the need for technology companies to stay ahead of the threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Exploited-by-Design-The-CoreGraphics-Zero-Day-Vulnerability-and-Apples-Swift-Response-ehn.shtml

  • https://www.theregister.com/security/2026/09/29/apple-patches-coregraphics-zero-day-already-exploited-in-targeted-attacks/5299721

  • https://nvd.nist.gov/vuln/detail/CVE-2026-86950

  • https://www.cvedetails.com/cve/CVE-2026-86950/


  • Published: Tue Sep 29 11:00:30 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us