Apple Patches Meta-Reported Zero-Day Linked to ‘Extremely Sophisticated Attack’
Apple on Monday released iOS and macOS updates to patch a zero-day vulnerability that may have been exploited in targeted attacks.
The flaw, tracked as CVE-2026-86950, is an out-of-bounds write issue in the CoreGraphics component that can be exploited for arbitrary code execution when it processes a specially crafted file.
Apple has not said how the malicious file is delivered, but because CoreGraphics handles 2D graphics and PDF rendering across the operating system, it could arrive via web pages, email attachments, or messaging apps, where automatic attachment and link previews could enable zero-click exploitation.
“Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27,” Apple said in its advisory.
No information has been shared on the attacks exploiting CVE-2026-86950, but Apple noted that it learned about the vulnerability from Meta’s product...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE