Skip to finding
important · Mobile

Apple patched a CoreGraphics crafted-file code-execution flaw after reports of targeted exploitation.

Affects

CoreGraphics in supported iPhones and iPads running the iOS 26 branch; Apple also shipped corresponding macOS fixes

CVE-2026-86950 is an out-of-bounds write in CoreGraphics that can execute code when an affected device processes a crafted file.

Detail and 4 sources

Apple says it is aware of possible exploitation against specifically targeted individuals.

Apple has not disclosed the file format, delivery channel, victim interaction, processing context, victims, or post-execution privilege.

Apple fixed the flaw in current supported updates.

Chain to watch
Attacker supplies a maliciously crafted file through an undisclosed delivery path→↓CoreGraphics processes the file→↓An out-of-bounds write corrupts memory→↓Arbitrary code executes in the processing context→↓The triggering format, delivery route, interaction requirement, processing context, victims, and post-execution privilege remain undisclosed; zero-click reachability is not established.
Unverified chainObtain Meta's technical analysis or incident forensics identifying the triggering format, delivery route, process, and interaction requirement.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 29, 2026