مركز جمع المعلومات

معلومات التهديدات

Apple patched a CoreGraphics zero-day used against targeted individuals.

Apple fixed CVE-2026-86950, an out-of-bounds write in CoreGraphics reported by Meta, after an "extremely sophisticated" targeted attack. Updates 26.7.1 and 15.8.1 are out.

هذا التقرير متاح بالإنجليزية فقط.

Apple has patched CVE-2026-86950, an out-of-bounds write in CoreGraphics that it says may have been exploited in an "extremely sophisticated attack against specific targeted individuals." Fixes shipped on September 28, 2026, according to Apple's advisory as reported by BleepingComputer, SecurityWeek and Help Net Security.


Meta Product Security reported the flaw. CoreGraphics handles 2D vector graphics, image rendering and PDF drawing across iOS, iPadOS, macOS, watchOS and tvOS. That reach matters. A malicious file processed by the framework could give an attacker arbitrary code execution on the device.


Apple has not published who is behind the attacks, how many people were targeted, or how the exploit was delivered. Coverage notes that image and PDF parsing bugs are often reachable through web pages, attachments and message previews, but that is a general property of the framework. It is not a confirmed delivery method here.


Apple fixed the issue with improved bounds checking in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.


What to do. Push the 26.7.1 and 15.8.1 updates to managed Apple devices now, and confirm compliance through MDM rather than assuming it. Prioritise high-risk users: executives, journalists, administrators and anyone with privileged access. Enable Lockdown Mode for individuals likely to be targeted by mercenary spyware. Watch for unexpected crashes in image or PDF handling on endpoints, and treat any device that shows them as suspect until it is patched and reviewed.


Attribution and exploitation scope remain unpublished. This post will not speculate beyond Apple's statement.

يتطلب صلاحية دخول.

سجل الأحداث المشفّر الكامل وإجراءات المعالجة متاحة بعد تسجيل الدخول.