-
Apple fixed CVE-2026-86950, a graphics bug in iOS and macOS that attackers have already used against specific people.
-
Install iOS or iPadOS 26.7.1, macOS Tahoe 26.7.1, or macOS Sequoia 15.8.1. Devices on version 27 are not affected.
-
Researchers have explained how the bug works. Whether it can hit a phone with zero taps is still unproven.

Apple has patched a serious flaw in iPhones, iPads, and Macs. The company says attackers already used it. The fixes arrived Monday, September 28. CISA added the bug to its list of known exploited flaws the next day. The Register counts it as Apple’s seventh exploited zero-day this year. If you haven’t updated yet, do it today.
Critical Flaw in Apple CoreGraphics
The flaw, tracked as CVE-2026-86950, affects Apple’s CoreGraphics framework. That is the part of Apple’s software that draws images, PDFs, and text. Apple calls it an out-of-bounds write.
Put simply, the software puts data somewhere in memory where it doesn’t belong. An attacker can use that mistake to run their own code. The trigger is a booby-trapped file.
Apple’s advisory says the bug may have been used in “an extremely sophisticated attack against specific targeted individuals.” That applies to devices running software older than iOS 27. Apple gave no details on who was targeted or how many people were hit. It has not named the attackers. The bug has a severity score of 8.8 out of 10.
Who Needs to Update
The patch covers a long list of devices:
- iPhone 11 and later
- iPad Pro 12.9-inch (from 3rd generation to later versions)
- All generations of iPad Pro 11-inch
- iPad Air (3rd gen and newer),
- iPad (8th gen and newer)
- iPad mini (5th gen and up).
- Macs running macOS Tahoe or macOS Sequoia
Apple’s newest releases, iOS 27.0.1, iPadOS 27.0.1, and macOS 27.0.1, don’t list this bug. Help Net Security reports that they appear unaffected. If you’re on anything older, update.
How the Bug Works
Security firm Calif published a full technical breakdown on Tuesday. Researchers Dion Blazakis, Josh Maine, and Anna Groza wrote it.
When a document shows text, the system turns each letter’s outline into whole numbers. One step in that process had no limit on how large a number could get. Two nearby pieces of code handled a too-large number in different ways. One capped it. The other let it wrap around.
That mismatch left the system setting aside too little memory. Later, it wrote past the end of that space. The attacker has some control over where the writer lands. Apple’s fix adds range checks to that conversion step everywhere it’s used.
Calif says a PDF with a specially built font can reach the flaw. The firm also posted working test code online. That could help defenders. It could also help copycats.
The WhatsApp Connection
Meta’s product security team reported the flaw. Since Meta owns WhatsApp, the company’s connection caused many observers to suspect the app. However, neither company has confirmed it. So, it’s unclear whether WhatsApp played any part.
Calif examined recent WhatsApp changes after Apple credited Meta Product Security for finding CVE-2026-86950. Researchers found new checks for embedded fonts inside PDF attachments.
The newer WhatsApp code looks for malformed or suspicious font data. It can flag those files as high risk before automatic processing continues.
That timing provides circumstantial evidence that PDFs containing malicious fonts may have been relevant to the vulnerability. However, it does not prove that WhatsApp delivered the real-world attacks.
Is this Vulnerability a Zero-Click?
Zero Day Engineering says the bug can fire with no tap if an app previews the file automatically. Other outlets say the evidence is thin. eSecurityPlanet didn’t find anything tying it to a specific app.
Calif compared two WhatsApp builds. The newer one added checks for odd fonts inside PDFs. Files that fail those checks are held back from automatic preview. That fits the attack Calif describes. But Calif says no one knows whether attackers paired this bug with other WhatsApp flaws to need less user action.
One more point matters. This bug alone doesn’t take over a phone. Zero Day Engineering says attackers still need a way out of the app’s security sandbox and a way to gain higher access. Currently, researchers have yet to publicly disclose the bugs.
The Flaw has Links to Zero-day Targeting Crypto Wallets
Blockchain security firm SlowMist called the update highly relevant to iPhone attacks it has tracked against wallet data. Its CISO went further and linked the patch to a zero-day used in crypto attacks.
Proof is missing, though. Apple’s notice doesn’t mention crypto. SlowMist’s September 19 report covered thefts from people who installed FomoPeek app versions 1.1 and 1.2. SlowMist and OKX found an iOS attack toolkit with eight exploit methods inside those builds. No public evidence shows this CoreGraphics bug was one of them.
What to Do Now
If you’re using any of the affected iPhone models, you’d need to update ASAP. To update your device, go to Settings on your iPhone or iPad, click General, and click Software Update. On your Mac, go to System Settings, General, and then Software Update. Turn on automatic updates while you’re there.
Most people are unlikely targets of attacks like this. Still, the bug is now documented in detail. Don’t open unexpected files, even from contacts. iPhone users also face social-engineering attacks that impersonate Apple support, including the AI voice scam targeting stolen iPhone owners with fake Apple support calls. People at higher risk, such as journalists and crypto holders, can consider turning on Apple’s Lockdown Mode.