Find notable cyber news and cases, enriched with sources, timelines, and signals.

Apple CoreGraphics out-of-bounds write security flaw (CVE-2026-86950)

Vulnerability
First reported
Last updated
Happening score
H score 25
1 unique sources, 1 articles

Summary

Hide ▲

Apple released updates for CVE-2026-86950, an out-of-bounds write in CoreGraphics that could enable arbitrary code execution on older iOS, iPadOS, and macOS versions. The flaw was tied to processing a maliciously crafted file and was said to have been possibly exploited in targeted attacks. Apple shipped fixes across iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.

Related Happenings

Coruna iOS exploit analysis ties updated Triangulation kernel exploit lineage

Technical Analysis
H score33 First: 26.03.2026 15:10 Last: 26.03.2026 15:10 Sources 1

About this happening: Coruna has been linked to an updated exploit lineage from Operation Triangulation, showing that a long-running iPhone attack framework continues to evolve and can stil...

Operation Triangulation updated iPhone espionage campaign

Campaign
H score41 First: 26.03.2026 15:10 Last: 26.03.2026 15:10 Sources 1

About this happening: The Operation Triangulation espionage lineage has resurfaced through Coruna, extending zero-click iPhone targeting to newer A17 and M3 devices and iOS 17.2...

Coruna watering-hole and fake-site exploitation campaign

Campaign
H score44 First: 26.03.2026 13:07 Last: 26.03.2026 13:07 Sources 1

About this happening: A suspected Russia-aligned nation-state actor is using Coruna in watering-hole attacks in Ukraine and a mass exploitation campaign, expanding the kit’s abuse beyon...

WebKit Same Origin Policy bypass (CVE-2026-20643)

Vulnerability
H score18 First: 18.03.2026 03:06 Last: 18.03.2026 03:06 Sources 1

About this happening: Apple fixed CVE-2026-20643, a WebKit flaw that let malicious web content bypass Same Origin Policy on iPhones, iPads, and Macs. The bug created a cross-origin...

Latest development: 18.03.2026 08:31

Apple released its first round of Background Security Improvements to address CVE-2026-20643 in WebKit, a cross-origin issue in the Navigation API that could bypass the same-origin policy when processing maliciously crafted web content. The flaw affects iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2, and Apple says it was addressed with improved input validation in iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), and macOS 26.3.2 (a). Apple also credits security researcher Thomas Espach with discovering and reporting the shortcoming.

Coruna (CryptoWaters) iOS exploit kit targeting iOS 13.0–17.2.1

Malware Activity
H score34 First: 04.03.2026 15:28 Last: 04.03.2026 15:28 Sources 1

About this happening: The Coruna iOS exploit kit is a continuously maintained successor to the Operation Triangulation framework and now incorporates five iOS exploit chains across 23...

Latest development: 26.03.2026 15:10

Kaspersky researchers said Coruna is a continuously maintained successor to the original Operation Triangulation iPhone framework, with updated kernel exploit code for CVE-2023-32434 and CVE-2023-38606, explicit support for Apple's A17 and M3 chips, and targeting up to iOS 17.2.

Timeline

  1. 28.09.2026 22:18 2 articles · 1h ago

    Apple patches CVE-2026-86950 in CoreGraphics

    Mitigation Patch Update

    Apple released security updates for older versions of iOS, iPadOS, and macOS to address CVE-2026-86950, an out-of-bounds write in CoreGraphics that could lead to arbitrary code execution when processing a maliciously crafted file. Apple said the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, said the flaw was addressed with improved bounds checking, and credited Meta Product Security with discovering and reporting it.

    Show sources