Apple Patches iPhone Zero-Day Linked to ‘Extremely Sophisticated’ Targeted Attack: Update Now

The CoreGraphics flaw could enable arbitrary code execution through a maliciously crafted file; Apple urges users on affected iOS versions to install the update

Apple patches iPhone zero-day exploited in targeted attacks
Apple has patched an iPhone zero-day after reporting sophisticated targeted exploitation Source: ChatGPT Plus Generated

Apple has patched an iPhone zero-day that it says may have been exploited in an 'extremely sophisticated attack' against specific targeted individuals. The vulnerability, tracked as CVE-2026-86950, affects CoreGraphics and can lead to arbitrary code execution when a device processes a maliciously crafted file.

Apple released iOS 26.7.1 and iPadOS 26.7.1 on 28 September to address the flaw. A day later, the US Cybersecurity and Infrastructure Security Agency added CVE-2026-86950 to its Known Exploited Vulnerabilities catalogue, which identifies vulnerabilities known to have been exploited in the wild.

Apple's public advisory does not identify the attackers, targeted individuals or countries involved. It also does not disclose how malicious files reached affected devices. Apple says the reported exploitation involved versions of iOS before iOS 27.

A Malicious File Could Trigger the Flaw

CVE-2026-86950 is an out-of-bounds write vulnerability in CoreGraphics, Apple's graphics framework for rendering and manipulating visual content.

In simple terms, an out-of-bounds write allows software to write data beyond an intended memory boundary. Apple says processing a maliciously crafted file may lead to arbitrary code execution, potentially allowing an attacker to run code on an affected device.

Apple addressed the vulnerability with improved bounds checking.

What remains unknown is how the malicious content was delivered. Apple has not publicly disclosed whether it reached targeted devices through a website, attachment, messaging service or another route.

There is also no confirmation that CVE-2026-86950 was used as a zero-click exploit.

Ensar Seker, chief information security officer at SOCRadar, told Dark Reading that a memory-corruption vulnerability of this type could potentially form part of a low-interaction or zero-click attack chain when combined with an appropriate delivery mechanism.

That is a technical possibility, not evidence that the attacks observed in connection with CVE-2026-86950 worked that way. The CVSS v3.1 vector associated with the vulnerability lists user interaction as required when assessing the flaw on its own.

Which iPhones Need the Update?

iOS 26.7.1 is available for the iPhone 11 and later.

Apple says the same CoreGraphics fix is included in iPadOS 26.7.1 for the third-generation iPad Air and later, fifth-generation iPad mini and later, eighth-generation iPad and later, first-generation 11-inch iPad Pro and later, and third-generation 12.9-inch iPad Pro and later.

Apple also patched CVE-2026-86950 in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. Both updates were released on 28 September.

Apple's advisory links the reported exploitation specifically to versions of iOS before iOS 27. Users who remain on iOS 26 should therefore install iOS 26.7.1 rather than leave the known vulnerability unpatched.

On an iPhone, users can check for available updates under Settings > General > Software Update.

CISA Lists the Flaw as Known Exploited

CISA added CVE-2026-86950 to its Known Exploited Vulnerabilities catalogue on 29 September. The catalogue identifies vulnerabilities for which there is evidence of exploitation in the wild.

CISA's CVE enrichment data assigns the flaw a CVSS v3.1 base score of 8.8, placing it in the High severity category. The scoring vector lists a network attack vector, low attack complexity, no privileges required and user interaction required.

Apple's disclosure does not indicate a broad campaign against iPhone users generally. Its wording instead describes an attack against specific targeted individuals.

The CISA listing confirms that CVE-2026-86950 is not merely a theoretical vulnerability. Evidence of exploitation exists, and Apple has released patches for affected versions of iOS, iPadOS and macOS.

Meta Product Security Reported the Zero-Day

Apple credited Meta Product Security with reporting CVE-2026-86950.

Meta told SecurityWeek that it routinely reports vulnerabilities discovered in third-party software so vendors can patch them. The company did not provide details about the attacks and did not say that WhatsApp or another Meta service was involved.

That distinction matters because WhatsApp disclosed a separate targeted exploit chain in 2025 involving CVE-2025-55177 and Apple's ImageIO vulnerability CVE-2025-43300. WhatsApp assessed that the two vulnerabilities may have been exploited together against specific targeted users, while researchers described the chain as capable of zero-click exploitation.

There is no public evidence connecting that 2025 incident to CVE-2026-86950. Neither Apple nor Meta has said WhatsApp was used to deliver the newly patched CoreGraphics vulnerability.

For anyone still running an affected version of iOS, the immediate step is straightforward: install the available security update.