A memory corruption bug in Apple’s CoreGraphics framework has been used in real attacks, and the US Cybersecurity and Infrastructure Security Agency has added it to its list of vulnerabilities under active attack. CISA placed CVE-2026-86950 in its Known Exploited Vulnerabilities (KEV) catalog on 29 September, one day after Apple shipped fixes for iPhone, iPad and Mac. Federal civilian agencies have until 2 October to act, and the entry carries a requirement to check devices for signs of prior compromise, not only to update them.
The flaw in brief
The weakness is an out-of-bounds write (CWE-787) in CoreGraphics, affecting iOS, iPadOS and macOS. According to the CVE record, opening or processing a specially crafted file can let an attacker run arbitrary code on the device. Apple says it corrected the problem by tightening bounds checks.
CISA’s enrichment of the CVE record scores it 8.8 under CVSS 3.1: reachable over a network, no privileges needed, but dependent on the target interacting with something, which fits a malicious file delivered by message, mail or web download. The agency’s SSVC assessment marks exploitation as active, the technical impact as total, and the attack as not automatable. Put plainly, a successful attempt can hand over the device, but it is not a worm-style bug that spreads by itself across the internet.
What is confirmed
Three points rest on primary sources:
- Exploitation. Apple’s own release notes say it has received a report that the bug may have been used in a highly advanced operation against a small number of chosen people. CISA’s catalog listing, which requires evidence of exploitation, converts that vendor hedge into an agency-level determination of active use.
- Affected and fixed versions. The CVE record lists iOS and iPadOS before 26.7.1 as affected, and on the Mac both macOS Sequoia before 15.8.1 and macOS Tahoe before 26.7.1. All three fixes were released on 28 September. The iPhone and iPad update covers iPhone 11 and later and a matching range of iPad Pro, iPad Air, iPad and iPad mini models.
- Compromise checks. The KEV entry is flagged for forensic triage under Binding Operational Directive 26-04, so federal agencies must establish whether a device was already breached and preserve evidence before patching.
What is not known
Apple ties the reported attack to iOS versions before iOS 27, but neither Apple nor CISA has said who carried it out, how many people were targeted, in which countries, or how the malicious file reached them. Whether the Mac variants were attacked as well, rather than simply sharing the vulnerable code, has not been stated. CISA records ransomware use as unknown, and no indicators of compromise accompany the listing. Apple’s phrasing is that the issue may have been exploited; the certainty comes from CISA’s decision to list it, not from any published technical account of the intrusions.
Who should move first
Our assessment: an attack described as aimed at a handful of selected people is unlikely to reach most employees, but the people it does reach tend to hold sensitive roles, such as senior leadership, legal and government-facing staff. Organisations with people in those roles, and managed-device fleets that still hold phones on iOS 26 rather than iOS 27, carry the most exposure. Because the bug sits in a system framework rather than in a single app, any path that gets a crafted file in front of CoreGraphics is a potential route in, and neither Apple nor CISA lists a workaround; updating is the fix.
What to do now
- Update every device. Move iPhones and iPads to iOS or iPadOS 26.7.1 or later, Macs on Tahoe to 26.7.1 or later, and Macs on Sequoia to 15.8.1 or later. Use your mobile device management console to confirm the installed build rather than trusting that users accepted the prompt.
- Chase the stragglers. Devices that have not checked in for days, loaner and shared devices, and personal phones used for work are where old builds hide. Consider blocking corporate access from builds below the fixed versions until they update.
- Prioritise high-risk users for triage. For people in the roles above, no indicators have been published, so treat any suspicion of compromise as a reason to preserve device evidence and seek specialist forensic help before wiping or restoring.
- Record what you did. If you are a federal civilian agency, the 2 October date and the triage requirement apply directly. Everyone else is outside the directive, but a documented update-and-check pass is the evidence you will want if a targeted user later reports a compromise.
The fix is already out and it is a routine update to install, so the main risk now is the gap between release and adoption. The CVE search lists other exploited flaws affecting mobile and desktop platforms.
Source: Cybersecurity and Infrastructure Security Agency (CISA)