Apple released updates for a zero-day it says was used in extremely sophisticated targeted attacks against specific individuals on iOS versions before iOS 27. Tracked as CVE-2026-20700, the flaw is an out-of-bounds write in CoreGraphics, the framework for two-dimensional graphics, image rendering, and text drawing across iOS, macOS, iPadOS, watchOS, and tvOS, and was reported by Meta Product Security. Processing a maliciously crafted file can lead to arbitrary code execution, and Apple addressed it with improved bounds checking. The affected device list is broad, spanning iPhone 11 and later, many iPad models, and Macs running macOS Sequoia 15.8.1 and Tahoe 26.7.1. Apple did not attribute the attacks or name the targeted individuals.