Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Apple Security Update Fixes Exploited CoreGraphics Zero-Day on iPhones and Macs

Apple Security Update Fixes Exploited CoreGraphics Zero-Day on iPhones and Macs

By:
Last updated:October 2, 2026
Human Written
  • Apple fixed CVE-2026-86950, a graphics bug in iOS and macOS that attackers have already used against specific people.

  • Install iOS or iPadOS 26.7.1, macOS Tahoe 26.7.1, or macOS Sequoia 15.8.1. Devices on version 27 are not affected.

  • Researchers have explained how the bug works. Whether it can hit a phone with zero taps is still unproven.

Apple Fixes Zero-Day Exploited Against iPhone and Mac Users

Apple has patched a serious flaw in iPhones, iPads, and Macs. The company says attackers already used it. The fixes arrived Monday, September 28. CISA added the bug to its list of known exploited flaws the next day. The Register counts it as Apple’s seventh exploited zero-day this year. If you haven’t updated yet, do it today.

Critical Flaw in Apple CoreGraphics

The flaw, tracked as CVE-2026-86950, affects Apple’s CoreGraphics framework. That is the part of Apple’s software that draws images, PDFs, and text. Apple calls it an out-of-bounds write.

Put simply, the software puts data somewhere in memory where it doesn’t belong. An attacker can use that mistake to run their own code. The trigger is a booby-trapped file.

Apple’s advisory says the bug may have been used in “an extremely sophisticated attack against specific targeted individuals.” That applies to devices running software older than iOS 27. Apple gave no details on who was targeted or how many people were hit. It has not named the attackers. The bug has a severity score of 8.8 out of 10.

Who Needs to Update

The patch covers a long list of devices:

  • iPhone 11 and later
  • iPad Pro 12.9-inch (from 3rd generation to later versions)
  • All generations of iPad Pro 11-inch  
  • iPad Air (3rd gen and newer), 
  • iPad (8th gen and newer)
  • iPad mini (5th gen and up).
  • Macs running macOS Tahoe or macOS Sequoia

Apple’s newest releases, iOS 27.0.1, iPadOS 27.0.1, and macOS 27.0.1, don’t list this bug. Help Net Security reports that they appear unaffected. If you’re on anything older, update.

How the Bug Works

Security firm Calif published a full technical breakdown on Tuesday. Researchers Dion Blazakis, Josh Maine, and Anna Groza wrote it.

When a document shows text, the system turns each letter’s outline into whole numbers. One step in that process had no limit on how large a number could get. Two nearby pieces of code handled a too-large number in different ways. One capped it. The other let it wrap around.

That mismatch left the system setting aside too little memory. Later, it wrote past the end of that space. The attacker has some control over where the writer lands. Apple’s fix adds range checks to that conversion step everywhere it’s used.

Calif says a PDF with a specially built font can reach the flaw. The firm also posted working test code online. That could help defenders. It could also help copycats.

The WhatsApp Connection

Meta’s product security team reported the flaw. Since Meta owns WhatsApp, the company’s connection caused many observers to suspect the app. However, neither company has confirmed it. So, it’s unclear whether WhatsApp played any part.

Calif examined recent WhatsApp changes after Apple credited Meta Product Security for finding CVE-2026-86950. Researchers found new checks for embedded fonts inside PDF attachments.

The newer WhatsApp code looks for malformed or suspicious font data. It can flag those files as high risk before automatic processing continues.

That timing provides circumstantial evidence that PDFs containing malicious fonts may have been relevant to the vulnerability. However, it does not prove that WhatsApp delivered the real-world attacks.

Is this Vulnerability a Zero-Click?

Zero Day Engineering says the bug can fire with no tap if an app previews the file automatically. Other outlets say the evidence is thin. eSecurityPlanet didn’t find anything tying it to a specific app.

Calif compared two WhatsApp builds. The newer one added checks for odd fonts inside PDFs. Files that fail those checks are held back from automatic preview. That fits the attack Calif describes. But Calif says no one knows whether attackers paired this bug with other WhatsApp flaws to need less user action.

One more point matters. This bug alone doesn’t take over a phone. Zero Day Engineering says attackers still need a way out of the app’s security sandbox and a way to gain higher access. Currently, researchers have yet to publicly disclose the bugs.

Blockchain security firm SlowMist called the update highly relevant to iPhone attacks it has tracked against wallet data. Its CISO went further and linked the patch to a zero-day used in crypto attacks.

Proof is missing, though. Apple’s notice doesn’t mention crypto. SlowMist’s September 19 report covered thefts from people who installed FomoPeek app versions 1.1 and 1.2. SlowMist and OKX found an iOS attack toolkit with eight exploit methods inside those builds. No public evidence shows this CoreGraphics bug was one of them.

What to Do Now

If you’re using any of the affected iPhone models, you’d need to update ASAP. To update your device, go to Settings on your iPhone or iPad, click General, and click Software Update. On your Mac, go to System Settings, General, and then Software Update. Turn on automatic updates while you’re there.

Most people are unlikely targets of attacks like this. Still, the bug is now documented in detail. Don’t open unexpected files, even from contacts. iPhone users also face social-engineering attacks that impersonate Apple support, including the AI voice scam targeting stolen iPhone owners with fake Apple support calls. People at higher risk, such as journalists and crypto holders, can consider turning on Apple’s Lockdown Mode.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.