⚡️ 0-Day Alert: Apple CoreGraphics RCE exploited in targeted attacks

Update iOS/iPadOS and macOS.

Share

CVE-2026-86950: out-of-bounds write in CoreGraphics parsing a maliciously crafted image/PDF, leading to arbitrary code execution.
Both iOS and macOS are vulnerable.

This AV is reachable through a wide variety of iOS native and 3rd party apps that render graphics, such as WhatsApp (first suspect due to report credit), Safari, iMessage, etc.

Zero-click where auto-preview renders the file.

However, the bug alone is not enough to compromise the device, and requires further chaining such as sandbox escape and EoP. These further bugs are not public.

Patched in iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1.