Zero News | Update Your iPhone Now: Apple Zero-Day Used in Targeted Attacks (CVE-2026-86950)
On September 28, 2026, Apple released emergency updates for a zero-day vulnerability that had already been used in real-world attacks.
Tracked as CVE-2026-86950, the flaw sits in CoreGraphics, the component that renders images, text and 2D graphics on iPhones, iPads and Macs.
What Happened
According to Apple, processing a specially crafted file on a vulnerable device can let an attacker run code on it.
Apple confirmed the flaw may have been exploited in an "extremely sophisticated attack" against "specific targeted individuals" on iOS versions before iOS 27. It was reported by Meta Product Security.
Is every iPhone, iPad and Mac in your organization already on the patched version?
Who Is at Risk
Apple has not disclosed who was behind the attack or how many people were targeted.
Attacks like this are typically linked to Pegasus-style spyware operations that target executives, journalists and employees in critical roles.

Which Versions Fix It
The flaw is fixed in iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1. It affects iPhone 11 and later; devices on iOS 27 are reported not to be affected.
Every device that postpones this update stays exposed to an attack method that is already in use.
Recommended Actions
Update all corporate and personal iPhones, iPads and Macs to iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1, macOS Sequoia 15.8.1 or iOS 27 without delay.
Enforce a minimum OS version through MDM and restrict access from outdated devices to corporate email and apps.
Enable Lockdown Mode for executives, finance teams and employees in critical roles.
Do not open files, images or PDF attachments from unknown senders.
Monitor devices for abnormal behavior with a Mobile Threat Defense (MTD) solution.
For more information, contact our experts at info@zerosecond.ae.
Zero Second | Zero News – Weekly cybersecurity briefing.
Zero News, prepared by Zero Second.





















Comments