Apple has rolled out critical security updates designed to patch a severe vulnerability affecting older iterations of its iOS, iPadOS, and macOS operating systems. According to the technology giant, this security flaw may have already been actively exploited in the wild as part of a series of highly targeted, sophisticated cyberattacks directed against specific individuals. The security flaw, which has been officially documented and tracked under the identifier CVE-2026-86950, specifically involves an out-of-bounds write weakness located within the CoreGraphics software component. CoreGraphics is a foundational framework responsible for handling vital rendering and graphical operations across Apple’s ecosystem. When an unpatched device processes a maliciously crafted file, this out-of-bounds write vulnerability can be triggered, potentially allowing an attacker to achieve arbitrary code execution on the compromised endpoint. Read Also: Why Isolated Security Testing Fails: The Rise of Autonomous Attack Chaining in Enterprise Defense Critical Unauthenticated RCE Vulnerability in Orkes Conductor Actively Exploited in the Wild In its advisory regarding the flaw, Apple explained that the security deficiency was successfully resolved through the implementation of significantly improved bounds checking within the affected software libraries. The company publicly credited the product security team at Meta for discovering and bringing the vulnerability to light, highlighting the ongoing collaboration within the broader technology industry to identify and mitigate complex threats before they can cause widespread harm. Providing further context into the nature of the threat, Apple noted that it is aware of intelligence indicating the vulnerability has been actively leveraged in the wild. Specifically, the company stated that the issue may have been exploited in an extremely sophisticated attack campaign directed against a very limited group of specific, targeted individuals running software versions preceding iOS 27. Despite confirming that targeted exploitation has taken place, Apple has deliberately withheld certain operational details. The company has not disclosed the precise number of individuals who were targeted, whether the individual attack attempts were ultimately successful in compromising the devices, or when the earliest instances of CVE-2026-86950 exploitation first occurred in the wild. Such details are frequently withheld during active investigations to protect the privacy of victims and prevent malicious actors from refining their intrusion methods. The discovery and subsequent patching of this vulnerability underscore the persistent nature of targeted mobile and desktop threats. Advanced spyware and zero-day exploit chains frequently rely on foundational system components like CoreGraphics because these libraries handle complex data types and parsing operations, making them prime targets for uncovering memory safety flaws. By abusing vulnerabilities in how files are rendered or processed, threat actors can sometimes bypass traditional perimeter security measures, delivering malicious payloads directly through standard user interactions such as opening a document, viewing an image, or browsing a compromised web page. This recent security event follows a similar incident earlier this year in February, when Apple was forced to issue an emergency patch to resolve a critical memory corruption issue residing in dyld, the dynamic linker responsible for loading and linking dynamic libraries for applications. That earlier vulnerability, tracked as CVE-2026-20700 and assigned a severe CVSS score of 7.8, was likewise confirmed by the company to have been aggressively weaponized in sophisticated cyberattacks targeting high-profile or high-risk users. Security researchers emphasize that zero-day vulnerabilities targeting specific individuals typically require significant resource investments, often indicating the involvement of sophisticated threat actors or commercial surveillance vendors capable of developing and maintaining complex exploit chains. Because these attacks often bypass standard user awareness, maintaining a robust patching routine remains one of the most effective defenses for endpoint security across enterprise and consumer environments alike. Users and enterprise administrators managing older supported devices running the impacted operating system versions are strongly advised to apply the newly released updates as quickly as possible to protect against potential exploitation attempts. Apple continues to monitor the threat landscape closely and encourages all device owners to ensure their software is consistently updated to the most current versions available. Post navigation Kiteworks Urges Customers to Preemptively Shut Down Systems Amid Credible Threat Intelligence