INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Apple CoreGraphics Zero-Day Exploit Released with Public Proof of Concept

| 2026-10-01 12:08 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
A highly sophisticated attack exploiting a zero-day vulnerability in Apple's CoreGraphics has been reported, with the first public proof-of-concept (PoC) released for CVE-2026-86950. The vulnerability affects iOS 26.7 and earlier versions before iOS 27, as well as iPadOS 26.7 and earlier and supported versions of macOS Tahoe and Sequoia. Apple has patched the issue with software updates, including iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. However, researchers have warned that attackers can trigger the flaw by tricking victims into opening malicious files sent through various channels, highlighting a potential risk to targeted individuals running older versions of iOS before iOS 27.
Technical Mitigations AI-generated
• Implement improved bounds checking to prevent out-of-bounds writes in CoreGraphics. • Validate and sanitize user-input files before processing them, especially for images and PDFs. • Regularly update operating systems (iOS, iPadOS, macOS) with the latest security patches.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-86950CVE-2026-86950
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎August 2025
Threat actors used a combination of vulnerabilities in WhatsApp's linked-device synchronization and an Apple CoreGraphics zero-day, CVE-2026-86950, to target fewer than 200 users.
organisation THN
victims 200 targeted users
‎September 28
Threat actors used the publicly disclosed Apple CoreGraphics zero-day CVE-2026-86950 to target specific individuals on versions of iOS before iOS 27.
infrastructure Ios
general_metric 27 iOS
organisation Meta Product Security
infrastructure Macos
‎September 30
Researchers Dion Blazakis, Josh Maine, and Anna Groza of Calif published an analysis on September 30 detailing their findings about a zero-day vulnerability in Apple CoreGraphics.
organisation Dion Blazakis
‎2026/10/01
Researchers at Calif published a proof-of-concept that triggers the Apple CoreGraphics zero-day CVE-2026-86950 on macOS and iOS.
organisation Apple CoreGraphics Zero-Day CVE-2026-86950
organisation PoC Released
organisation Apple
organisation CoreGraphics
organisation Apple CoreGraphics
infrastructure Ios
infrastructure Macos
infrastructure 26.7
organisation macOS Tahoe
infrastructure 26.7.1
infrastructure 15.8.1
organisation Meta Product Security
organisation Meta
organisation The Hacker News
organisation WhatsApp
organisation PDF
organisation Apple CoreGraphics PoC Emerges
organisation iPhones
organisation Macs
organisation TrueType
organisation PoC
organisation SecurityAffairs
infrastructure 26.37.73
infrastructure 26.38.74
organisation The WhatsApp Question
‎October 2
The U.S. Cybersecurity and Infrastructure Security Agency added the Apple CoreGraphics zero-day vulnerability CVE-2026-86950 to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply the fix by October 2.
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
Tactical Metrics
Metrics
infrastructure
‎Ios
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎26.7
Software Version
Metrics
infrastructure
‎26.7.1
Software Version
Metrics
infrastructure
‎15.8.1
Software Version
Metrics
infrastructure
‎26.37.73
Software Version
Metrics
infrastructure
‎26.38.74
Software Version
Metrics
victims
200
Targeted Users
Intelligence Sources