Yaamlabs

Vulnerabilities

Apple CoreGraphics zero-day: get iPhones to 26.7.1

CVE-2026-86950, a CoreGraphics flaw Apple says was used against targeted people, is fixed in iOS 26.7.1. Which devices, MDM rules and Lockdown Mode steps.

On September 28, Apple shipped iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1 to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics. Apple says it is aware of a report that the flaw "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27". Meta Product Security found it. The Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities (KEV) catalog on September 29 and gave US federal agencies until October 2 to patch.

You are affected if you manage iPhones or iPads still on iOS or iPadOS 26, or Macs on Tahoe or Sequoia. Apple does not list the flaw for iOS 27, iPadOS 27 or macOS Golden Gate 27, and reporting from SecurityWeek and MacRumors reads that as the 27 releases being unaffected. The catch for fleets is that five older iPad models cannot run iPadOS 27 at all, so 26.7.1 is the only fix they will get.

How it works

CoreGraphics (also called Quartz 2D) is the framework that draws 2D graphics on Apple systems, including images and PDF pages. Most apps that display content use it underneath, from mail and chat apps to the browser and file previews, so a crafted file has many ways to reach it.

An out-of-bounds write means the code writes data past the end of the memory buffer it was given. When the parser trusts a size or offset field inside a crafted file, it can be led to overwrite neighbouring memory, and a careful exploit shapes that overwrite into control of the process. Apple's description is that "processing a maliciously crafted file may lead to arbitrary code execution", fixed "with improved bounds checking". The vulnerability is scored 8.8 under CVSS 3.1 (vector AV:N/AC:L/PR:N/UI:R), where UI:R means some user action, such as receiving or opening the file, is assumed.

SecurityWeek points out that because CoreGraphics renders previews automatically, a file delivered through a web page, an email attachment or a messaging app could in practice need no tap at all. Apple has not said how the exploit was delivered, and has published no technical details or indicators of compromise.

What attackers are doing

Almost nothing is public. Apple used the same "extremely sophisticated attack against specific targeted individuals" wording for earlier zero-days tied to targeted spyware, which points to a small number of chosen people rather than mass exploitation. Neither Apple nor Meta has named targets, dates or an attacker.

The Meta credit has a precedent. In August 2025, WhatsApp said a flaw in its iOS and macOS apps (CVE-2025-55177) was likely chained with Apple's ImageIO bug CVE-2025-43300, also an out-of-bounds write in image processing, in zero-click attacks on fewer than 200 people. There is no public evidence yet that CVE-2026-86950 was used the same way, so treat the parallel as context only.

For most businesses the practical reading matches that history: a random employee's phone is unlikely to be hit, but executives, lawyers, finance staff on sensitive deals, and anyone travelling to places where they could be singled out are the people this kind of exploit is bought for.

What to do

Know which version each device needs

  • iPhone 11 and later on iOS 26: iOS 26.7.1, or move to iOS 27.0.1.
  • iPad Pro 12.9-inch (3rd generation), iPad Pro 11-inch (1st generation), iPad Air (3rd generation), iPad (8th generation) and iPad mini (5th generation): these cannot run iPadOS 27, so iPadOS 26.7.1 is the target.
  • Macs on Tahoe: 26.7.1. Macs on Sequoia: 15.8.1. Apple's September 28 release list has no update for Sonoma or older, so any Mac still there should be upgraded or retired.
  • iPhones older than the iPhone 11 are outside the list of fixed devices. Take them off anything that touches work data.

On a single iPhone, Settings, General, About shows the version; Settings, General, Software Update installs it. The fix only takes effect after the restart, so a phone with a downloaded but pending update is still exposed.

Enforce it through MDM

In Microsoft Intune, open the iOS/iPadOS compliance policy and set Minimum OS version under Device Properties to 26.7.1. Devices below it become noncompliant, and if you have a Conditional Access policy that requires compliant devices, they lose access to Microsoft 365 until they update. A 27.x device passes the same rule, so there is no need for separate policies per branch. Do the same on the macOS compliance policy with 15.8.1 for Sequoia (Tahoe devices sit above it).

To make supervised devices install the update rather than only nag, use Apple's declarative software update enforcement (the com.apple.configuration.softwareupdate.enforcement.specific declaration, iOS 17 and macOS 14 or later). Set TargetOSVersion to 26.7.1 and TargetLocalDateTime to a deadline such as the evening of October 2; if the user has not installed it by then, the device installs it itself. Intune, Jamf and other MDMs expose this as an update policy with a target version and deadline. Staying on 26.7.1 instead of 27 is a legitimate choice where app compatibility is still being tested.

Lockdown Mode for high-risk staff

Apple's Lockdown Mode (Settings, Privacy & Security, Lockdown Mode, then Turn On & Restart; on a Mac, System Settings, Privacy & Security) blocks most message attachment types other than certain images, video and audio, turns off link previews and blocks some complex web technologies. That cuts the file-parsing surface this kind of exploit relies on. Apple has not said whether it would have stopped this exploit, so it is extra hardening on top of the update, not a substitute.

Two points for admins. Lockdown Mode is a user choice, so MDM cannot switch it on for people. And a device in Lockdown Mode cannot be newly enrolled in MDM or install new configuration profiles, so enrol the device first; an already enrolled device stays managed.

Checking whether a device was hit

There is no public indicator to search for. Apple sends threat notifications, by iMessage and email to the Apple Account and on the account page, to people it believes were targeted by mercenary spyware, so ask high-risk staff to report any such notice straight away. If one arrives, or a high-risk user's device behaved oddly before the update, do not wipe it first. Keep the device, take an encrypted backup, and have a mobile forensics specialist review it, for example with Amnesty International's Mobile Verification Toolkit (MVT). Also review that person's recent sign-ins, MFA approvals and mailbox rules, since an attacker with the phone may already have used its sessions.

The lesson for patching phones

Apple now ships fixes on two branches at once, 26.x and 27.x, and some devices can only take one of them. A report that only asks whether a device runs the latest major version flags every iOS 26 device, including the patched ones, and says nothing about whether each device has this fix. Minimum version rules in MDM answer that directly, and a deadline-based enforcement policy closes the gap between "update available" and "update installed and restarted".

Our mobile penetration testing covers the iOS and Android apps your staff carry and the data they leave on the device, and our safeguarding and hardening work sets up the compliance rules and update enforcement that keep the fleet current. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: Apple, security content of iOS 26.7.1 and iPadOS 26.7.1, Apple security releases, Full Disclosure, APPLE-SA-09-28-2026-1, CISA KEV alert, CISA KEV catalog, SecurityWeek, Help Net Security, The Register, BleepingComputer, MacRumors, TidBITS, Tenable CVE entry, Apple, About Lockdown Mode, Microsoft Intune iOS/iPadOS compliance settings, Apple software update declarative configuration, The Hacker News on CVE-2025-43300.

Back to the blog, or read this post on the full site.