Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
Brief
Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available.
Apple patched a zero-day vulnerability, tracked as CVE-2026-86950 , in CoreGraphics that attackers may have exploited to target specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when the system processes a specially crafted file.
The vulnerability affects iOS 26. 7 and earlier versions before iOS 27, as well as iPadOS 26. 7 and earlier and supported versions of macOS Tahoe and macOS Sequoia. Apple released iOS 26.
- 1, iPadOS 26.
- 1, macOS Tahoe 26.
- 1 and macOS Sequoia 15.
- 1 to address the issue.
“Processing a maliciously crafted file may lead to arbitrary code execution.
