Apple has fixed a zero-day in its Core Graphics framework that it says may already have been used against a narrow set of targets.
Tracked as CVE-2026-86950, the flaw is an out-of-bounds write that can let an attacker run code when a device opens a maliciously crafted file. Apple said it patched the issue with improved bounds checking and credited Meta Product Security for reporting it.
Apple said it had a report of exploitation against a handful of specific people, described only as an extremely sophisticated campaign aimed at devices running versions of iOS before iOS 27. It gave no detail on the targets or the timing.
Install the update that carries the patch: iOS and iPadOS 26.7.1, or macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. The newest releases, iOS 27.0.1, iPadOS 27.0.1 and macOS Golden Gate 27.0.1, carry no published CVE-numbered fixes and do not appear to be affected.
Core Graphics handles drawing, color management, image data and PDF parsing, so a parsing bug there can be reached through ordinary files. Given the reported exploitation, users on affected versions should update now.
