Apple CoreGraphics flaw exploited in targeted attacks
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
An actively exploited out-of-bounds write in Apple CoreGraphics lets attackers achieve code execution via malicious files on iOS, iPadOS and macOS.
NCSC-NL has published an advisory for CVE-2026-86950, an out-of-bounds write vulnerability in Apple's CoreGraphics component affecting iOS, iPadOS, and macOS. The flaw can be triggered by processing a specially crafted file, allowing an attacker to achieve arbitrary code execution on the target device. The vulnerability carries a CVSS v3 score of 8.8.
Notably, NCSC-NL states the vulnerability has been used in targeted attacks against iOS versions prior to iOS 27, indicating active in-the-wild exploitation rather than theoretical risk. Apple has released updates that improve bounds checking in CoreGraphics to prevent the out-of-bounds memory writes.
Defenders should prioritize patching affected Apple devices (iOS, iPadOS, macOS) to the latest versions as soon as possible, given confirmed exploitation in targeted attacks. Organizations handling sensitive data on Apple devices, or those at risk of targeted surveillance/espionage activity, should treat this as a priority patch.
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0397.html
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,537 reports from 153 sources, 482 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs