Apple has issued security updates for CVE-2026-86950, an out-of-bounds write in CoreGraphics that can lead to arbitrary code execution when a device processes a maliciously crafted file. Apple says it is aware of a report that the issue may have been used in an extremely sophisticated attack against specific targeted individuals.

The company fixed the issue with improved bounds checking. Available updates include iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 for supported devices.

Defensive takeaway

Organizations should treat this as a targeted-exploitation patch: deploy the applicable Apple updates promptly, confirm fleet coverage through device management, and ensure users who handle sensitive material are not left on older supported releases. Apple has not published details on the targets, timing, or observed compromise outcomes, so incident teams should avoid assumptions beyond the vendor’s stated exploitation warning.

Source: The Hacker News; Apple security release notes.

By Allan