Apple Patches CoreGraphics Flaw Possibly Exploited Against Specific Targeted Individuals (CVE-2026-86950)
Scope: iOS, iPadOS, and macOS Devices Running Versions Prior to iOS 27 and macOS Tahoe 26.7.1
Severity: Amber
Apple released security updates on September 28, 2026 for CVE-2026-86950, an out-of-bounds write vulnerability in the CoreGraphics component that can lead to arbitrary code execution when a device processes a maliciously crafted file. Apple stated it is aware of a report that the issue may have been exploited in an "extremely sophisticated attack" against specific targeted individuals on versions of iOS prior to iOS 27, language the company reserves for cases involving commercial mercenary spyware rather than ordinary cybercrime. Apple has not disclosed how many individuals were targeted, whether any attempts succeeded, or when exploitation may have first begun, and credited Meta's Product Security team with discovering and reporting the flaw. While the targeted nature of this attack means most ordinary users are at low risk, individuals in government, journalism, human rights work, or other roles that make them plausible spyware targets should treat this update as an immediate priority rather than routine maintenance. All users should update affected devices to the latest available iOS, iPadOS, or macOS Tahoe release as soon as possible.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.