Apple: Critical Apple Zero-Day Vulnerability Actively Exploited in Attacks

Apple: Critical Apple Zero-Day Vulnerability Actively Exploited in Attacks

Apple Patches Critical Zero-Day Vulnerability in iOS and iPadOS

Apple has released iOS 26.7.1 and iPadOS 26.7.1 to address a zero-day vulnerability (CVE-2026-86950) that may have been exploited in a highly targeted attack against specific individuals. The flaw, discovered in the CoreGraphics framework, could allow attackers to execute arbitrary code on vulnerable devices by tricking users into processing a maliciously crafted file.

The vulnerability affects iPhone 11 and later models, as well as multiple iPad Pro, iPad Air, iPad, and iPad mini devices. Apple confirmed that the exploit was used against users running iOS versions prior to iOS 27, suggesting a spyware or surveillance-driven attack commonly targeting journalists, activists, executives, and government personnel.

The issue stems from an out-of-bounds write flaw in CoreGraphics, where software writes data outside allocated memory boundaries. Successful exploitation could grant attackers arbitrary code execution, enabling unauthorized commands, data access, or further device compromise.

Apple mitigated the flaw with improved bounds checking and released the patches on September 28, 2026. The company did not disclose details about the attackers, victims, or attack methods, citing ongoing investigations.

The vulnerability was reported by Meta Product Security, underscoring the persistent threat of zero-day exploits in file-processing components, particularly in targeted espionage campaigns. Users and organizations are advised to update affected devices via Settings > General > Software Update.

Source: https://cybersecuritynews.com/apple-zero-day-vulnerability-exploited/

Apple TPRM report: https://www.rankiteo.com/company/apple

"id": "app1790670237",
"linkid": "apple",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': ['Journalists',
                                               'Activists',
                                               'Executives',
                                               'Government personnel'],
                        'industry': 'Consumer Electronics, Software',
                        'location': 'Global',
                        'name': 'Apple',
                        'size': 'Large Enterprise',
                        'type': 'Technology Company'}],
 'attack_vector': 'Maliciously crafted file',
 'customer_advisories': 'Update affected devices via Settings > General > '
                        'Software Update.',
 'date_publicly_disclosed': '2026-09-28',
 'date_resolved': '2026-09-28',
 'description': 'Apple has released iOS 26.7.1 and iPadOS 26.7.1 to address a '
                'zero-day vulnerability (CVE-2026-86950) in the CoreGraphics '
                'framework that may have been exploited in a highly targeted '
                'attack. The flaw could allow attackers to execute arbitrary '
                'code on vulnerable devices by tricking users into processing '
                'a maliciously crafted file.',
 'impact': {'systems_affected': 'Arbitrary code execution'},
 'initial_access_broker': {'high_value_targets': ['Journalists',
                                                  'Activists',
                                                  'Executives',
                                                  'Government personnel']},
 'investigation_status': 'Ongoing',
 'motivation': ['Spyware', 'Surveillance', 'Targeted Espionage'],
 'post_incident_analysis': {'corrective_actions': 'Improved bounds checking in '
                                                  'software update',
                            'root_causes': 'Out-of-bounds write flaw in '
                                           'CoreGraphics framework'},
 'recommendations': 'Users and organizations are advised to update affected '
                    'devices via Settings > General > Software Update.',
 'references': [{'source': 'Apple Security Update'},
                {'source': 'Meta Product Security'}],
 'response': {'communication_strategy': 'Public disclosure via security update '
                                        'notes',
              'containment_measures': 'Improved bounds checking in '
                                      'CoreGraphics framework',
              'remediation_measures': 'Software update (iOS 26.7.1, iPadOS '
                                      '26.7.1)',
              'third_party_assistance': 'Meta Product Security (vulnerability '
                                        'reporting)'},
 'title': 'Apple Patches Critical Zero-Day Vulnerability in iOS and iPadOS '
          '(CVE-2026-86950)',
 'type': 'Zero-Day Exploit',
 'vulnerability_exploited': 'CVE-2026-86950 (Out-of-bounds write in '
                            'CoreGraphics framework)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.