Trusence Every claim has a source
Last updated 29 September 2026 Search Türkçe
← All stories
Security

Apple issues emergency fix for CoreGraphics zero-day under active attack

Targeted attacks on specific iOS users push Apple to ship urgent patches across iOS, iPadOS and macOS.

Apple has released emergency security updates for iOS, iPadOS and macOS to patch CVE-2026-20700, an out-of-bounds write bug in the CoreGraphics framework that has been actively exploited in highly targeted attacks. The vulnerability allows arbitrary code execution via a maliciously crafted file, and Apple says the attacks have been used against specific individuals on iOS versions prior to iOS 27. Fixes are shipping in iOS 26.7.1 and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1, covering a wide range of recent iPhones, iPads and Macs. The company credits Meta Product Security with discovering the issue and notes it has been mitigated through stricter bounds checking in CoreGraphics. This is the second in-the-wild zero-day Apple has resolved this year, following a dyld arbitrary code execution bug patched in February, underscoring the need for Apple platforms to be kept on current security releases.

Why it matters

The flaw sits in a core graphics component shared across Apple’s platforms, so a single bug opened a path for silent compromise of many recent iPhones, iPads and Macs through a malicious file. With Apple confirming it was used in highly targeted, sophisticated attacks and noting it is the second in-the-wild zero-day this year, the updates highlight both the focus on individual high-value targets and the growing importance of staying on current security releases.

Sources

  • BleepingComputer