Apple patched a CoreGraphics crafted-file code-execution flaw after reports of targeted exploitation.
Affects
CoreGraphics in supported iPhones and iPads running the iOS 26 branch; Apple also shipped corresponding macOS fixes
CVE-2026-86950 is an out-of-bounds write in CoreGraphics that can execute code when an affected device processes a crafted file.
Detail and 4 sources
Apple says it is aware of possible exploitation against specifically targeted individuals.
Apple has not disclosed the file format, delivery channel, victim interaction, processing context, victims, or post-execution privilege.
Apple fixed the flaw in current supported updates.
Chain to watch
Attacker supplies a maliciously crafted file through an undisclosed delivery path→↓CoreGraphics processes the file→↓An out-of-bounds write corrupts memory→↓Arbitrary code executes in the processing context→↓The triggering format, delivery route, interaction requirement, processing context, victims, and post-execution privilege remain undisclosed; zero-click reachability is not established.
Unverified chainObtain Meta's technical analysis or incident forensics identifying the triggering format, delivery route, process, and interaction requirement.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.