{"id":3205,"date":"2026-09-28T20:07:39","date_gmt":"2026-09-28T20:07:39","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3205"},"modified":"2026-09-28T20:07:39","modified_gmt":"2026-09-28T20:07:39","slug":"apple-patches-coregraphics-flaw-possibly-exploited-in-targeted-attacks","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3205","title":{"rendered":"Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 28, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Endpoint Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhO5I5gnKOqAs0ZCjgQnQirUHdSjRqGZRMp-Fioy684EzZWuQm72wSrCW1hWZEYlvvOXoCtkQyr3sB48AoZ71PM6tMCsz_AGZmEYZz8u2AbrH1gpjutU-mFtDQpuJcI_pKEG9q4-cZEo7T3Yp7hyphenhyphen4_MCZvloRnVKszE7rjTDUKZBaH1eQ47-K0fPno50T3S\/s1700-nu-rw-lo-l85-e365\/apple-0day.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks.<\/p>\n<p>The vulnerability, tracked as <strong>CVE-2026-86950<\/strong>, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file.<\/p>\n<p>The iPhone maker said the issue was addressed with improved bounds checking. It credited Meta Product Security with discovering and reporting the issue.<\/p>\n<p>\u00abApple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27,\u00bb it added.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>However, the company offered no details on how many individuals were targeted, if any of those attempts were successful, or when the first instance of CVE-2026-86950 exploitation occurred.<\/p>\n<p>The shortcoming has been addressed in the following devices and operating system versions &#8211;<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/support.apple.com\/en-us\/149226\" target=\"_blank\">iOS 26.7.1 and iPadOS 26.7.1<\/a><\/strong> &#8211; iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later<\/li>\n<li><strong><a href=\"https:\/\/support.apple.com\/en-us\/149228\" target=\"_blank\">macOS Tahoe 26.7.1<\/a><\/strong> &#8211; Macs running macOS Tahoe<\/li>\n<li><strong><a href=\"https:\/\/support.apple.com\/en-us\/149229\" target=\"_blank\">macOS Sequoia 15.8.1<\/a><\/strong> &#8211; Macs running macOS Sequoia<\/li>\n<\/ul>\n<p>Earlier this February, Apple addressed a memory corruption issue in dyld (CVE-2026-20700, CVSS score: 7.8) that it said had been weaponized in sophisticated cyber attacks.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 28, 2026Vulnerability \/ Endpoint Security Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3206,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[618,24,3568,128,70,57,3569,113],"class_list":["post-3205","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-apple","tag-attacks","tag-coregraphics","tag-exploited","tag-flaw","tag-patches","tag-possibly","tag-targeted"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3205","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3205"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3205\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3206"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3205"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3205"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3205"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}