Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’

Apple has issued emergency updates to patch a critical vulnerability in its iOS and macOS operating systems, which may have been exploited in targeted attacks against specific individuals. The flaw, tracked as CVE-2026-86950, is an out-of-bounds write issue in the CoreGraphics component that can be used for arbitrary code execution when processing specially crafted files.

The vulnerable component handles 2D graphics and PDF rendering across the operating system, which means it’s possible to deliver malicious files through web pages, email attachments, or messaging apps. In fact, Apple warns that automatic attachment and link previews could enable zero-click exploitation, where users don’t even need to click on a file or link for their device to be compromised.

Apple has confirmed that the vulnerability was reported by Meta’s product security team, which is noteworthy given a similar incident last year involving WhatsApp and Apple’s ImageIO zero-day. However, it’s unclear whether CVE-2026-86950 was exploited through WhatsApp this time around, as Meta hasn’t commented on the matter.

The patched flaw has been identified in iOS versions prior to 27, with Apple releasing updates for iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. Notably, while both iOS and macOS are affected, Apple’s advisory suggests that attacks have only been observed against the former.

The patching of CVE-2026-86950 is significant, as it marks the ninth Apple product flaw added to the CISA’s KEV catalog this year. While the latest versions of iOS 27 and macOS Golden Gate 27 are not affected, users running earlier versions should update their devices as soon as possible.

The exploitation of this vulnerability highlights the importance of staying up-to-date with software patches and updates, particularly for critical components like CoreGraphics that handle sensitive functions across the operating system. While the exact details of the targeted attacks remain unclear, it’s evident that threat actors continue to evolve and adapt their tactics to exploit vulnerabilities in widely used software.

As a result, it’s essential for users to be cautious when interacting with files and links from unknown sources, even if they appear legitimate. Apple’s advisory serves as a reminder that cybersecurity is an ongoing effort that requires vigilance and attention to detail. By keeping our devices updated and being mindful of potential threats, we can reduce the risk of falling victim to sophisticated attacks like this one.


Source: SecurityWeek — 2026-09-29