Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices.
Excerpt from the primary source: BleepingComputer
Who is affected
Home users · Small businesses · Security professionals
Affected technology: iOS & iPadOS
Why it matters
Source reporting says attackers are already exploiting this, so exposed iOS & iPadOS systems are at immediate risk.
Automated: stated only from CISA listings and the exploitation evidence in the sources below.
What you should do · Act now
Treat this as an emergency. Identify every system running iOS & iPadOS, apply the vendor's fix or published mitigations immediately, and check for signs of compromise. Patching alone does not remove an attacker who already got in.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Original reporting
Related
Chrome Beta for iOS Update
Hi everyone! We've just released Chrome Beta 156 (156.0.8078.3) for iOS; it'll become available on App Store in the next few days. You can see a partial list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Chrome Release Team Google Chrome…
Chrome Stable for iOS Update
Hi everyone! We've just released Chrome Stable 155 (155.0.8059.24) for iOS; it'll become available on App Store in the next few hours. This release includes stability and performance improvements. You can see a full list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Chrome Release Team Google Chrome…
Mobile malware warning from Ukrainian researchers includes iPhone exploit kit
'Hit and run' iPhone malware known as DarkSword is part of a wave of Russian attacks on iOS and Android devices, according to Ukraine's SSSCIP.
Apple Multiple Products Out-of-Bounds Write Vulnerability (CVE-2026-86950) is being actively exploited, CISA warns
CISA added CVE-2026-86950 (Apple Multiple Products) to its Known Exploited Vulnerabilities catalog on September 29, 2026, which means there is reliable evidence of exploitation in the wild. Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
CISA lists this as exploited in the wild. Unpatched macOS and iOS & iPadOS systems are exposed to active attacks now.
Treat this as an emergency.
