Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

CVE-2026-86950: Apple CoreGraphics Zero-Day in iOS, iPadOS & macOS (Update to 26.7.1)

High CVE-2026-86950, CVE-2026-65400 — Apple patched a CoreGraphics zero-day used in targeted attacks against iPhones. Which iOS, iPadOS, and macOS versions fix it, plus the macOS Screen Sharing login bypass (CVE-2026-65400) also being exploited.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Opening a maliciously crafted file (an image or PDF, for example) can run code on an unpatched iPhone, iPad, or Mac. Apple says it was used in “extremely sophisticated” targeted attacks. Update to iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, or macOS Sequoia 15.8.1. Separately, if you use macOS Screen Sharing, make sure you have the August fix for CVE-2026-65400.

CVE-2026-86950CoreGraphics out-of-bounds write: crafted file → arbitrary code execution
Fixed iniOS 26.7.1 & iPadOS 26.7.1 · macOS Tahoe 26.7.1 · macOS Sequoia 15.8.1 (released 2026-09-28)
Exploited?Yes, targeted attacks per Apple; CISA KEV 2026-09-29
CVE-2026-65400macOS Screen Sharing login without valid credentials, from the network
Fixed inmacOS Tahoe 26.6.1 / 26.7 · Sequoia 15.7.9 · Sonoma 14.8.9 · Golden Gate 27
Exploited?Yes, CISA KEV 2026-08-18

What CVE-2026-86950 is

CoreGraphics is the system library Apple devices use to draw images and PDFs. It runs whenever you preview an attachment, view a picture in Messages, or open a document. A bounds-checking mistake lets a crafted file write past the end of a buffer and take control of the process drawing it.

Apple’s wording, “an extremely sophisticated attack against specific targeted individuals”, usually means commercial spyware aimed at journalists, executives, officials, and activists. Most people weren’t targeted, but once a fix is public the bug gets studied and reused, so everyone should update.

Apple notes the attacks it saw were against iOS versions before iOS 27.

Am I affected?

  • iPhone / iPad: Settings → General → About → iOS Version. Anything below 26.7.1 on the iOS 26 line needs updating.
  • Mac: Apple menu → About This Mac, or in Terminal: sw_vers -productVersion. Tahoe below 26.7.1 or Sequoia below 15.8.1 needs updating.

Covered devices for iOS 26.7.1: iPhone 11 and later, iPad Pro 12.9-inch (3rd gen) and later, iPad Pro 11-inch (1st gen) and later, iPad Air (3rd gen) and later, iPad (8th gen) and later, and iPad mini (5th gen) and later. Older devices that can’t run iOS 26 don’t get this fix.

How to patch

  • iPhone / iPad: Settings → General → Software Update. Turn on Automatic Updates and Security Responses & System Files while you’re there.
  • Mac: System Settings → General → Software Update.
  • Managed fleets: push the update through your MDM (Jamf, Intune, Kandji, etc.) with a deadline. Don’t leave it to users.

If you think you may be a target (journalist, executive, activist), consider turning on Lockdown Mode (Settings → Privacy & Security → Lockdown Mode). It disables many of the file-parsing features these attacks rely on.

Also exploited: macOS Screen Sharing bypass (CVE-2026-65400)

In August, Apple fixed a bug that let anyone who could reach a Mac’s Screen Sharing (VNC) service on the network log in without valid credentials. CISA added it to the exploited list on 2026-08-18. It’s fixed in macOS Tahoe 26.6.1 / 26.7, Sequoia 15.7.9, and Sonoma 14.8.9.

If you’re on an older macOS, or can’t update right away:

  • Turn Screen Sharing off: System Settings → General → Sharing → Screen Sharing.
  • Never expose port 5900 to the internet. Use a VPN (WireGuard, Tailscale) to reach Macs remotely.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories