Apple patches CoreGraphics zero-day flaw exploited in attacks

Apple has just released critical security patches to fix a serious vulnerability in its CoreGraphics framework, which was exploited by sophisticated attackers in targeted attacks on iOS devices. The flaw, tracked as CVE-2026-20700, is an out-of-bounds write weakness that could allow hackers to crash apps, corrupt data, or even gain remote code execution on vulnerable devices.

The issue affects a wide range of Apple devices, including iPhone 11 and later models, iPad Pro, iPad Air, iPad mini, and Macs running macOS Sequoia and Tahoe. The vulnerability was discovered by Meta Product Security in the CoreGraphics framework, which is used for two-dimensional vector graphics, image rendering, and text drawing across various Apple operating systems.

The exploitation of out-of-bounds write vulnerabilities can have severe consequences, including crashing a program or corrupting data. In the worst-case scenario, hackers could use this flaw to gain remote code execution by writing data outside the allocated memory buffer. Apple has confirmed that it is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

The company has addressed this issue with improved bounds checking to prevent exploitation in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Apple’s prompt action is a testament to its commitment to protecting users from emerging threats.

This vulnerability is just the latest in a string of high-severity issues that have been exploited by attackers this year. In February, Apple patched another zero-day flaw tracked as CVE-2026-20700 in dyld (the Dynamic Link Editor used by Apple operating systems). The company has also fixed several other vulnerabilities, including a high-severity Beats Studio Buds flaw and older iPhones and iPads against four vulnerabilities targeted in cyberespionage and crypto-theft attacks using the Coruna exploit kit.

Given that this vulnerability is likely to be exploited only in highly targeted attacks, it’s essential for Apple users to install these security updates promptly to prevent potential ongoing attacks. Users should also remain vigilant and keep their devices up-to-date with the latest security patches to minimize the risk of exploitation. By taking these precautions, users can ensure the continued security and integrity of their Apple devices.


Source: Bleeping Computer — 2026-09-29