Apple Patches CoreGraphics Zero-Day CVE-2026-86950

Apple confirmed targeted exploitation on pre-iOS 27 devices, and SlowMist says the fix likely closes a hole used against crypto wallet users.

By Vivek • • 3 Min Read • 0 • Follow on Google News Add to Preferred Source
Apple patched CVE-2026-86950, a CoreGraphics zero-day exploited on pre-iOS 27 iPhones

Apple on Monday released iOS 26.7.1 and iPadOS 26.7.1 to patch a CoreGraphics zero-day that may have been exploited in targeted attacks against iPhone users.

The vulnerability is tracked as CVE-2026-86950 and has a CVSS score of 8.8. It is an out-of-bounds write in CoreGraphics, the framework Apple’s operating systems use to render and manipulate 2D graphics. According to Apple, processing a maliciously crafted file can lead to arbitrary code execution.

Apple said it is aware of a report that the flaw may have been exploited in an “extremely sophisticated attack” targeting specific individuals running earlier versions of iOS. The company credited Meta Product Security with reporting the bug. It did not name the attackers or the targets, nor did it say how many devices were compromised.

An out-of-bounds write occurs when software stores data beyond the edge of the memory region allocated for it. An attacker who controls that overflowing data can corrupt neighboring memory and redirect the program. A booby-trapped file then runs attacker code as soon as CoreGraphics parses it. Apple fixed the issue with improved bounds checking.

Apple has not explained how the malicious file reached its victims. Ensar Seker, CISO at SOCRadar, told Dark Reading that a memory-corruption bug of this kind can enable a low-interaction or even zero-click attack chain when paired with a suitable delivery mechanism.

On Tuesday, blockchain security firm SlowMist said Apple’s update is “highly relevant” to iOS exploitation activity it has tracked targeting sensitive crypto wallet data. SlowMist CISO 23pds went further in a separate post. He tied the patch to a zero-day he said was used in attacks involving crypto wallets.

Apple’s advisory does not mention cryptocurrency, and neither company has published evidence linking CVE-2026-86950 to a specific theft. Cyber Kendra has not independently verified the connection.

SlowMist’s warning follows its September 19 report of crypto assets stolen from users who had installed versions 1.1 and 1.2 of FomoPeek. A joint investigation by SlowMist and OKX found an iOS kernel exploitation framework with eight exploit methods inside those builds. SlowMist has not said the FomoPeek campaign used the CoreGraphics flaw.

The US Cybersecurity and Infrastructure Security Agency added CVE-2026-86950 to its Known Exploited Vulnerabilities catalog on Tuesday, citing evidence of active exploitation.

The iOS and iPadOS fix covers:

  • iPhone 11 and later
  • iPad Pro 12.9-inch (third generation and later)
  • iPad Pro 11-inch (first generation and later)
  • iPad Air (third generation and later)
  • iPad (eighth generation and later)
  • iPad mini (fifth generation and later)

Apple shipped the same patch in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1.

iOS 27.0.1, iPadOS 27.0.1, and macOS Golden Gate 27.0.1 shipped without any published CVE entries. Reports say that the current generation does not appear to be affected.

Users who remain on iOS 26 should install 26.7.1 or move to iOS 27. SlowMist also advised crypto holders to avoid apps from untrusted sources and to be wary of unexpected files and links opened in Safari or in-app browsers.

Community Discussion

Join the conversation. Ask questions, share solutions, and help others.

0 Comments

Be the first to start the discussion!

Leave a Comment

Your email address will not be published. Required fields are marked *

We respect your privacy, your information is safe with us.

Latest Articles

View all