• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    CVE-2026-86950

    Apple Fixes CoreGraphics Flaw Used in Targeted Attacks

    Medyc cyberattack

    Polish Medical Software Hit by Cyberattack, Patient Data Stolen

    Airbus Cybersecurity SAS

    France Awards Airbus 25-Year Contract for Military Network Gateways

    AI service security

    Hackers Are Stealing AI Keys. The Cost Can Reach $600,000

    Renfe cyberattack

    Renfe Cyberattack Hits Spain’s Rail Network as AI Role Probed

    CVE-2026-88771

    Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack

    Kiteworks shutdown advisory

    Kiteworks Systems Restored After Threat Warning, Vulnerability Found

    Dyfed-Powys Police cyberattack

    Cyberattack Disrupts Police Systems in Wales, Staff Data Under Investigation

    weekly roundup The Cyber Express TCE Sep 2026

    The Cyber Express Weekly Roundup: ShinyHunters’ FBI Breach Claim, North Korea’s WaterPlum Campaign, and the EU KIDS Act

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    AI service security

    Hackers Are Stealing AI Keys. The Cost Can Reach $600,000

    AI security risks

    Sam Altman at UN Security Council: 6 AI Security Risks the World Cannot Ignore

    AI-enabled cyber attacks

    AI Gives Hackers an Edge Defenders Still Can’t Match, NCSC Warns

    Fraudulent SIM cards

    India’s DoT Warns Citizens Over SIM Fraud and IMEI Tampering

    EU cybersecurity incidents

    EU Cybersecurity Response Hampered by Critical Information Gaps

    EU KIDS Act

    Children Under 13 Could Be Barred From Social Media Under New EU Plan

    GUARD Act

    US House Passes Bill to Help Police Track Down Scammers Targeting Seniors

    Emergency Security Protocol

    EU Plans ‘Article 4’-Style Security Protocol for Cyberattacks and Hybrid Threats

    Cyber Resilience Act, CRA, EU, EU Sanctions, Iran, Chinese Hacking,

    EU’s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Act

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    weekly roundup September 18 2026

    The Cyber Express Weekly Roundup: Hiscox’s SMB Warning, a Nintendo Switch Flaw, and a Record Deepfake Takedown

    threat intelligence

    Cyble, UAE Cyber Security Council Unite Against Rising Cyber Threats

    Ukraine cybersecurity

    Zelensky Appoints Ihor Klymenko to Lead Ukraine’s Cybersecurity Center

    UK cyberattack rate

    UK Small Firms Bear Brunt of Rising Cyberattacks, Hiscox Finds

    Cyber Yodha Campaign

    Cyble and DRONA Launch New Push to Close India’s Cybersecurity Gap

    UK Ukraine AI partnership

    Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data

    Hims & Hers lawsuit

    FTC Sues Hims & Hers Over Health Data Privacy, Billing Practices

    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    Sunil Varkey

    Sunil Varkey Joins Hexaware Technologies as EVP & CISO

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    CVE-2026-86950

    Apple Fixes CoreGraphics Flaw Used in Targeted Attacks

    Medyc cyberattack

    Polish Medical Software Hit by Cyberattack, Patient Data Stolen

    Airbus Cybersecurity SAS

    France Awards Airbus 25-Year Contract for Military Network Gateways

    AI service security

    Hackers Are Stealing AI Keys. The Cost Can Reach $600,000

    Renfe cyberattack

    Renfe Cyberattack Hits Spain’s Rail Network as AI Role Probed

    CVE-2026-88771

    Citrix NetScaler Hit by Two Critical RCE Flaws Already Under Attack

    Kiteworks shutdown advisory

    Kiteworks Systems Restored After Threat Warning, Vulnerability Found

    Dyfed-Powys Police cyberattack

    Cyberattack Disrupts Police Systems in Wales, Staff Data Under Investigation

    weekly roundup The Cyber Express TCE Sep 2026

    The Cyber Express Weekly Roundup: ShinyHunters’ FBI Breach Claim, North Korea’s WaterPlum Campaign, and the EU KIDS Act

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    AI service security

    Hackers Are Stealing AI Keys. The Cost Can Reach $600,000

    AI security risks

    Sam Altman at UN Security Council: 6 AI Security Risks the World Cannot Ignore

    AI-enabled cyber attacks

    AI Gives Hackers an Edge Defenders Still Can’t Match, NCSC Warns

    Fraudulent SIM cards

    India’s DoT Warns Citizens Over SIM Fraud and IMEI Tampering

    EU cybersecurity incidents

    EU Cybersecurity Response Hampered by Critical Information Gaps

    EU KIDS Act

    Children Under 13 Could Be Barred From Social Media Under New EU Plan

    GUARD Act

    US House Passes Bill to Help Police Track Down Scammers Targeting Seniors

    Emergency Security Protocol

    EU Plans ‘Article 4’-Style Security Protocol for Cyberattacks and Hybrid Threats

    Cyber Resilience Act, CRA, EU, EU Sanctions, Iran, Chinese Hacking,

    EU’s 24-Hr Vulnerability Reporting Rules Take Effect Friday, a Year Before the Rest of the Cyber Resilience Act

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    weekly roundup September 18 2026

    The Cyber Express Weekly Roundup: Hiscox’s SMB Warning, a Nintendo Switch Flaw, and a Record Deepfake Takedown

    threat intelligence

    Cyble, UAE Cyber Security Council Unite Against Rising Cyber Threats

    Ukraine cybersecurity

    Zelensky Appoints Ihor Klymenko to Lead Ukraine’s Cybersecurity Center

    UK cyberattack rate

    UK Small Firms Bear Brunt of Rising Cyberattacks, Hiscox Finds

    Cyber Yodha Campaign

    Cyble and DRONA Launch New Push to Close India’s Cybersecurity Gap

    UK Ukraine AI partnership

    Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data

    Hims & Hers lawsuit

    FTC Sues Hims & Hers Over Health Data Privacy, Billing Practices

    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    Sunil Varkey

    Sunil Varkey Joins Hexaware Technologies as EVP & CISO

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Apple Fixes CoreGraphics Flaw Used in Targeted Attacks

Ashish Khaitan by Ashish Khaitan
September 29, 2026
in Firewall Daily, Vulnerabilities, Vulnerability News
0
CVE-2026-86950
585
SHARES
3.2k
VIEWS
Share on LinkedInShare on Twitter

Apple has released iOS 26.7.1 and iPadOS 26.7.1 to address CVE-2026-86950, a CoreGraphics vulnerability the company says may have been used in targeted attacks. The updates came out on September 28, 2026, along with matching fixes for macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. 

The flaw is in CoreGraphics, a core Apple framework that handles graphics rendering. According to Apple, processing a maliciously crafted file may lead to arbitrary code execution. In practice, an attacker could run their own code on a vulnerable device by getting it to open a specially prepared file. 

Apple described the root cause as an out-of-bounds write issue. This type of memory bug happens when software writes data past the edge of the memory area set aside for it. The company said it fixed the problem with improved bounds checking. 

In its advisory, Apple stated: “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.” 

Apple credited Meta Product Security with reporting the vulnerability. 

Devices Covered by the iOS and iPadOS Update 

The iOS 26.7.1 and iPadOS 26.7.1 fix is available for iPhone 11 and later. On the iPad side, it covers: 

  • iPad Pro 12.9-inch (3rd generation and later) 
  • iPad Pro 11-inch (1st generation and later) 
  • iPad Air (3rd generation and later) 
  • iPad (8th generation and later) 
  • iPad mini (5th generation and later) 

CVE-2026-86950 Also Reaches macOS 

The issue is not limited to iOS and iPadOS. Apple published separate security notes for macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, both released on September 28, 2026. Each describes the same CoreGraphics flaw, the same arbitrary code execution risk, and the same out-of-bounds write fix. Each also credits Meta Product Security. 

The macOS notes repeat Apple’s statement that the bug may have been exploited against specific individuals on versions of iOS before iOS 27. The Tahoe update applies to macOS Tahoe, and the Sequoia update applies to macOS Sequoia.

Advisory Rates CVE-2026-86950 as High Risk 

A separate advisory, also dated September 28, 2026, classifies the problem as a remote code execution vulnerability in Apple products. It warns that a remote attacker could exploit the flaw to trigger remote code execution on a targeted system. 

The advisory rates the risk level as High for two reasons. The flaw is being exploited in an extremely sophisticated attack on specific targeted individuals running versions of iOS before iOS 27. A crafted file is also enough to achieve arbitrary code execution. 

The advisory lists the following as affected: 

  • Versions prior to iOS 26.7.1 and iPadOS 26.7.1 
  • Versions prior to macOS Tahoe 26.7.1 
  • Versions prior to macOS Sequoia 15.8.1 

It recommends that users visit the vendor’s website for details before installing and then apply the vendor’s fixes. The related Apple support pages are: 

  • https://support.apple.com/en-hk/149226 
  • https://support.apple.com/en-hk/149228 
  • https://support.apple.com/en-hk/149229 

Apple’s Disclosure Approach 

Apple says that, to protect customers, it does not disclose, discuss, or confirm security issues until it has investigated them and patches or releases are available. The company references vulnerabilities by CVE-ID when possible, as it did with CVE-2026-86950. Recent releases are listed on its security releases page, and more information is on its Product Security page. 

Apple’s notes also state that information about products not made by Apple, or about independent websites it does not control, is provided without recommendation or endorsement. Apple directs users to contact those vendors for further details. 

Since attackers have reportedly already used the flaw, owners of supported iPhones and iPads should install iOS 26.7.1 or iPadOS 26.7.1. Mac users should update to macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1, depending on which version they run. 

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: CoreGraphicsCVE-2026-86950iOSiPadOSmacOSThe Cyber ExpressThe Cyber Express News
Previous Post

Polish Medical Software Hit by Cyberattack, Patient Data Stolen

Q1 2026 Threat Reports

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

CVE-2026-86950
Firewall Daily

Apple Fixes CoreGraphics Flaw Used in Targeted Attacks

September 29, 2026
Medyc cyberattack
Cyber News

Polish Medical Software Hit by Cyberattack, Patient Data Stolen

September 29, 2026
Airbus Cybersecurity SAS
Firewall Daily

France Awards Airbus 25-Year Contract for Military Network Gateways

September 29, 2026
AI service security
Cyber Essentials

Hackers Are Stealing AI Keys. The Cost Can Reach $600,000

September 29, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information