
CVE-2026-86950: Apple CoreGraphics — Remote Code Execution Risk (June 2026)
CVE-2026-86950 — Apple CoreGraphics
CVE-2026-86950 is a critical vulnerability in the Apple CoreGraphics framework affecting iOS, iPadOS, and macOS. The flaw allows remote attackers to execute arbitrary code by delivering a specially crafted file, and has been exploited in targeted attacks prior to disclosure. No CVSS score is published, but Apple rates this as critical and exploitation in the wild is confirmed.
Attack Vector
Attackers exploit CVE-2026-86950 by sending a malicious file (e.g., image or PDF) that triggers an out-of-bounds write in CoreGraphics when processed by the device. No user interaction beyond opening or previewing the file is required. The vulnerability can be exploited remotely via email, messaging apps, or web downloads. There are no public indicators of compromise, but targeted exploitation has been observed.
Who Is at Risk
All Apple devices running iOS, iPadOS, and macOS versions prior to the latest June 2026 security updates are vulnerable. Devices confirmed at risk include iPhones and iPads on iOS versions before iOS 27, and Macs running unpatched macOS releases. Apple is the affected vendor; exploitation has so far been limited to highly targeted attacks, but risk of broader exploitation is now elevated.
Patch & Mitigate
- Patch: Update immediately to iOS 27, iPadOS 27, and the latest macOS security update released June 2026. Delaying patching increases risk of compromise.
- Workaround: No viable workaround is available. Disabling file preview features may reduce risk but is not sufficient.
- Detect: Monitor for unexpected CoreGraphics crashes or abnormal file handling activity in system logs. Review device logs for signs of out-of-bounds memory access or abnormal process behavior after file receipt.
MITRE ATT&CK
- TA0001 — Initial Access: Attackers deliver malicious files to gain code execution on target devices.
- T1204 — User Execution: Exploitation occurs when a user opens or previews a crafted file.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

