Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: coregraphics (1 article)Clear

Apple patches exploited CoreGraphics zero-day enabling code execution from a malicious file

Apple released updates for a zero-day it says was used in extremely sophisticated targeted attacks against specific individuals on iOS versions before iOS 27. Tracked as CVE-2026-20700, the flaw is an out-of-bounds write in CoreGraphics, the framework for two-dimensional graphics, image rendering, and text drawing across iOS, macOS, iPadOS, watchOS, and tvOS, and was reported by Meta Product Security. Processing a maliciously crafted file can lead to arbitrary code execution, and Apple addressed it with improved bounds checking. The affected device list is broad, spanning iPhone 11 and later, many iPad models, and Macs running macOS Sequoia 15.8.1 and Tahoe 26.7.1. Apple did not attribute the attacks or name the targeted individuals.

Check
Push the latest iOS, iPadOS, and macOS updates to all managed Apple devices now, prioritizing individuals at elevated risk of targeted attacks.
Affected
Apple devices before the fixed versions can be driven to arbitrary code execution by opening a maliciously crafted file through the CoreGraphics out-of-bounds write.
Fix
Apply the CoreGraphics fixes across iOS, iPadOS, and macOS, enforce update deadlines via MDM, and consider Lockdown Mode for high-risk users.