Apple has patched a CoreGraphics zero-day after warning that attackers may already have used the bug to compromise a small number of carefully chosen targets. The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write flaw in CoreGraphics, Apple's framework for handling graphics across its operating systems. According to Apple's advisory, processing a maliciously crafted file could allow an attacker to execute arbitrary code on a vulnerable device.
Apple patches CoreGraphics zero-day already exploited in targeted attacks
About this summary. This is a short, independently written summary of an article first published by The Register. Cyber Security News did not report or verify the underlying story. Read the original: https://www.theregister.com/security/2026/09/29/apple-patches-coregraphics-zero-day-already-exploited-in-targeted-attacks/5299721

Source attribution: headline and facts are from The Register (theregister.com). Summary method: excerpt of the source description. See our source attribution policy.





