Apple fixes zero-day used in targeted attacks

 

Apple fixes zero-day used in targeted attacks

Apple has released security updates to fix a zero-day vulnerability that was exploited in highly targeted attacks against iPhone users.

The flaw, tracked as CVE-2026-20700, affects CoreGraphics, a system framework used for graphics, images, and text. Apple said the vulnerability could allow a specially crafted file to execute malicious code.

The company said it is aware of a report that the flaw was exploited in an “extremely sophisticated” attack against specific individuals using versions of iOS before iOS 27.

The issue is caused by an out-of-bounds write, which can allow attackers to write data outside an allocated memory area. Apple fixed the vulnerability with improved bounds checking.

The affected devices include iPhone 11 and later, as well as several generations of iPad Pro, iPad Air, iPad, and iPad mini. Macs running macOS Sequoia and macOS Tahoe are also affected.

Apple has addressed the flaw in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.


Back to the list