High CVE-2026-86950, CVE-2026-65400 — Apple patched a CoreGraphics zero-day used in targeted attacks against iPhones. Which iOS, iPadOS, and macOS versions fix it, plus the macOS Screen Sharing login bypass (CVE-2026-65400) also being exploited.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Opening a maliciously crafted file (an image or PDF, for example) can run code on an unpatched iPhone, iPad, or Mac. Apple says it was used in “extremely sophisticated” targeted attacks. Update to iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, or macOS Sequoia 15.8.1. Separately, if you use macOS Screen Sharing, make sure you have the August fix for CVE-2026-65400.
| CVE-2026-86950 | CoreGraphics out-of-bounds write: crafted file → arbitrary code execution |
|---|---|
| Fixed in | iOS 26.7.1 & iPadOS 26.7.1 · macOS Tahoe 26.7.1 · macOS Sequoia 15.8.1 (released 2026-09-28) |
| Exploited? | Yes, targeted attacks per Apple; CISA KEV 2026-09-29 |
| CVE-2026-65400 | macOS Screen Sharing login without valid credentials, from the network |
| Fixed in | macOS Tahoe 26.6.1 / 26.7 · Sequoia 15.7.9 · Sonoma 14.8.9 · Golden Gate 27 |
| Exploited? | Yes, CISA KEV 2026-08-18 |
CoreGraphics is the system library Apple devices use to draw images and PDFs. It runs whenever you preview an attachment, view a picture in Messages, or open a document. A bounds-checking mistake lets a crafted file write past the end of a buffer and take control of the process drawing it.
Apple’s wording, “an extremely sophisticated attack against specific targeted individuals”, usually means commercial spyware aimed at journalists, executives, officials, and activists. Most people weren’t targeted, but once a fix is public the bug gets studied and reused, so everyone should update.
Apple notes the attacks it saw were against iOS versions before iOS 27.
sw_vers -productVersion. Tahoe below 26.7.1 or Sequoia below 15.8.1 needs updating.Covered devices for iOS 26.7.1: iPhone 11 and later, iPad Pro 12.9-inch (3rd gen) and later, iPad Pro 11-inch (1st gen) and later, iPad Air (3rd gen) and later, iPad (8th gen) and later, and iPad mini (5th gen) and later. Older devices that can’t run iOS 26 don’t get this fix.
If you think you may be a target (journalist, executive, activist), consider turning on Lockdown Mode (Settings → Privacy & Security → Lockdown Mode). It disables many of the file-parsing features these attacks rely on.
In August, Apple fixed a bug that let anyone who could reach a Mac’s Screen Sharing (VNC) service on the network log in without valid credentials. CISA added it to the exploited list on 2026-08-18. It’s fixed in macOS Tahoe 26.6.1 / 26.7, Sequoia 15.7.9, and Sonoma 14.8.9.
If you’re on an older macOS, or can’t update right away:
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.