Apple has released emergency security updates for older versions of its operating systems to address CVE-2026-86950, a CoreGraphics vulnerability that the company says may have been exploited in targeted attacks. Both SANS ISC and The Hacker News report that the flaw is already being exploited, with Apple describing it as an "extremely sophisticated attack against specific targeted individuals" on iOS versions before iOS 27.

The vulnerability is an out-of-bounds write in the CoreGraphics component that could allow arbitrary code execution when processing a maliciously crafted file, according to The Hacker News. Apple says it fixed the issue with improved bounds checking and credited Meta Product Security for discovering and reporting it. Apple did not disclose how many people were targeted, whether any attacks succeeded, or when the first exploitation occurred.

The patches cover iOS 26.7.1 and iPadOS 26.7.1 for a range of iPhones and iPads, as well as macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. SANS ISC notes that only older branches include the security fix, while iOS and macOS 27 are not affected. The two sources agree on the scope, though The Hacker News provides more technical detail and also notes a previous dyld vulnerability (CVE-2026-20700) patched in February.