INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Apple Patches CoreGraphics Zero Day Exploited in Sophisticated Targeted Attacks

| 2026-09-29 06:18 CRITICAL MEDIUM EXPLOITED VULNERABILITY VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
On September 28, Apple attributed the discovery of CVE-2026-86950 to its Meta Product Security team. The vulnerability affects a broad range of Apple devices, including iPhones dating back to the iPhone 11 and multiple generations of iPads, as well as Macs running macOS Sequoia 15.8.1 and Tahoe 26.7.1. According to reports, this zero-day was exploited in an "extremely sophisticated attack against specific targeted individuals" on versions of iOS before iOS 27, with Apple stating that processing a maliciously crafted file may lead to arbitrary code execution. The vulnerability has been fixed in the latest software updates for affected devices.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2025-43529, CVE-2025-55177 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

sa•••••.organizations
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-43529CVE-2025-43529 CVE-2025-55177CVE-2025-55177 CVE-2025-14174CVE-2025-14174 CVE-2025-20701CVE-2025-20701 CVE-2026-86869CVE-2026-86869 CVE-2025-24200CVE-2025-24200 CVE-2025-31200CVE-2025-31200 CVE-2025-31201CVE-2025-31201 CVE-2026-86950CVE-2026-86950 CVE-2025-43300CVE-2025-43300 CVE-2025-24085CVE-2025-24085 CVE-2025-24201CVE-2025-24201 CVE-2026-20700CVE-2026-20700
Target & Sectors
IL
Incident Timeline
‎February 2025
Researchers at The Citizen Lab discovered and reported the CVE-2025-24200 CoreGraphics zero-day vulnerability, which was allegedly exploited in a targeted attack against an individual.
organisation CVE-2025-24200
organisation The Citizen Lab
‎2025/09/29
Threat actors used the Apple ImageIO zero-day vulnerability (CVE-2025-43300) in conjunction with a previously disclosed WhatsApp iOS and macOS app vulnerability (CVE-2025-55177) to carry out zero-click attacks targeting fewer than 200 users.
infrastructure Ios
infrastructure Macos
vulnerability CVE-2025-55177
vulnerability CVE-2025-43300
organisation WhatsApp
victims 200 users
vulnerability CVE-2025-24200
organisation CVE-2025
vulnerability CVE-2025-24085
vulnerability CVE-2025-24201
organisation CVE-2025-31200
vulnerability CVE-2025-31201
vulnerability CVE-2025-43529
vulnerability CVE-2025-14174
‎September 28
The Meta Product Security team discovered and attributed the CVE-2026-86950 vulnerability to Apple on September 28.
vulnerability CVE-2026-86950
organisation the Meta Product Security
‎Sep 28, 2026
Threat actors exploited a previously unknown vulnerability in Apple's CoreGraphics library, allowing them to execute arbitrary code on affected systems.
‎September 29, 2026
Apple patched zero-day CVE-2026-86950 in CoreGraphics, which was exploited in sophisticated targeted attacks against specific iOS users.
infrastructure Ios
vulnerability CVE-2026-86950
organisation CoreGraphics
organisation Apple
‎2026/09/29
Apple has released iOS and macOS updates to patch a zero-day vulnerability, CVE-2026-86950, an out-of-bounds write issue in the CoreGraphics component that can be exploited for arbitrary code execution when it processes a specially crafted file.
infrastructure Ios
infrastructure Macos
infrastructure 26.7.1
infrastructure 15.8.1
infrastructure 26.7
organisation macOS Tahoe
organisation Macs
organisation iPhones
organisation iPads
organisation Apple
organisation CoreGraphics
organisation Sequoia
organisation Meta Product Security
organisation Vulnerability / Endpoint Security
infrastructure 11 iPhone
organisation iPad
infrastructure 12.9-inch
organisation Meta
organisation KEV
organisation Jamf
organisation SOCRadar
organisation WhatsApp
organisation CVE-2025
organisation PDF
organisation SecurityWeek
organisation Apple Patches CoreGraphics Zero Day
organisation IR
organisation iPhone
organisation CVSS
infrastructure 7.8
organisation Apple Patches CoreGraphics Zero-Day
organisation SecurityAffairs
organisation NSO Group
organisation Vulnerability Weaponized
organisation Seker
organisation iPad Air
organisation NFL
organisation CHANEL
‎Oct. 2
Threat actors are using the CVE-2026-86950 vulnerability to potentially compromise affected agencies by October 2.
vulnerability CVE-2026-86950
Tactical Metrics
Metrics
infrastructure
‎Ios
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
victims
200
Users
Metrics
infrastructure
‎26.7.1
Software Version
Metrics
infrastructure
‎15.8.1
Software Version
Metrics
infrastructure
‎26.7
Software Version
Metrics
infrastructure
11
Iphone
Metrics
infrastructure
‎12.9-inch
Software Version
Metrics
infrastructure
‎7.8
Software Version
Intelligence Sources