Apple CoreGraphics out-of-bounds write security flaw (CVE-2026-86950)
Vulnerability
Summary
Hide ▲
Show ▼
Apple released updates for CVE-2026-86950, an out-of-bounds write in CoreGraphics that could enable arbitrary code execution on older iOS, iPadOS, and macOS versions. The flaw was tied to processing a maliciously crafted file and was said to have been possibly exploited in targeted attacks. Apple shipped fixes across iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.
Related Happenings
Coruna iOS exploit analysis ties updated Triangulation kernel exploit lineage
Technical Analysis
H score33
First: 26.03.2026 15:10
Last: 26.03.2026 15:10
Sources 1
About this happening:
Coruna has been linked to an updated exploit lineage from Operation Triangulation, showing that a long-running iPhone attack framework continues to evolve and can stil...
Coruna iOS exploit analysis ties updated Triangulation kernel exploit lineage
Technical AnalysisAbout this happening: Coruna has been linked to an updated exploit lineage from Operation Triangulation, showing that a long-running iPhone attack framework continues to evolve and can stil...
Operation Triangulation updated iPhone espionage campaign
Campaign
H score41
First: 26.03.2026 15:10
Last: 26.03.2026 15:10
Sources 1
About this happening:
The Operation Triangulation espionage lineage has resurfaced through Coruna, extending zero-click iPhone targeting to newer A17 and M3 devices and iOS 17.2...
Operation Triangulation updated iPhone espionage campaign
CampaignAbout this happening: The Operation Triangulation espionage lineage has resurfaced through Coruna, extending zero-click iPhone targeting to newer A17 and M3 devices and iOS 17.2...
Coruna watering-hole and fake-site exploitation campaign
Campaign
H score44
First: 26.03.2026 13:07
Last: 26.03.2026 13:07
Sources 1
About this happening:
A suspected Russia-aligned nation-state actor is using Coruna in watering-hole attacks in Ukraine and a mass exploitation campaign, expanding the kit’s abuse beyon...
Coruna watering-hole and fake-site exploitation campaign
CampaignAbout this happening: A suspected Russia-aligned nation-state actor is using Coruna in watering-hole attacks in Ukraine and a mass exploitation campaign, expanding the kit’s abuse beyon...
WebKit Same Origin Policy bypass (CVE-2026-20643)
Vulnerability
H score18
First: 18.03.2026 03:06
Last: 18.03.2026 03:06
Sources 1
About this happening:
Apple fixed CVE-2026-20643, a WebKit flaw that let malicious web content bypass Same Origin Policy on iPhones, iPads, and Macs. The bug created a cross-origin...
WebKit Same Origin Policy bypass (CVE-2026-20643)
VulnerabilityAbout this happening: Apple fixed CVE-2026-20643, a WebKit flaw that let malicious web content bypass Same Origin Policy on iPhones, iPads, and Macs. The bug created a cross-origin...
Latest development: 18.03.2026 08:31
Apple released its first round of Background Security Improvements to address CVE-2026-20643 in WebKit, a cross-origin issue in the Navigation API that could bypass the same-origin policy when processing maliciously crafted web content. The flaw affects iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2, and Apple says it was addressed with improved input validation in iOS 26.3.1 (a), iPadOS 26.3.1 (a), macOS 26.3.1 (a), and macOS 26.3.2 (a). Apple also credits security researcher Thomas Espach with discovering and reporting the shortcoming.
Coruna (CryptoWaters) iOS exploit kit targeting iOS 13.0–17.2.1
Malware Activity
H score34
First: 04.03.2026 15:28
Last: 04.03.2026 15:28
Sources 1
About this happening:
The Coruna iOS exploit kit is a continuously maintained successor to the Operation Triangulation framework and now incorporates five iOS exploit chains across 23...
Coruna (CryptoWaters) iOS exploit kit targeting iOS 13.0–17.2.1
Malware ActivityAbout this happening: The Coruna iOS exploit kit is a continuously maintained successor to the Operation Triangulation framework and now incorporates five iOS exploit chains across 23...
Latest development: 26.03.2026 15:10
Kaspersky researchers said Coruna is a continuously maintained successor to the original Operation Triangulation iPhone framework, with updated kernel exploit code for CVE-2023-32434 and CVE-2023-38606, explicit support for Apple's A17 and M3 chips, and targeting up to iOS 17.2.
Timeline
-
28.09.2026 22:18 2 articles · 1h ago
Apple patches CVE-2026-86950 in CoreGraphics
Mitigation Patch UpdateApple released security updates for older versions of iOS, iPadOS, and macOS to address CVE-2026-86950, an out-of-bounds write in CoreGraphics that could lead to arbitrary code execution when processing a maliciously crafted file. Apple said the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, said the flaw was addressed with improved bounds checking, and credited Meta Product Security with discovering and reporting it.
Show sources
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks — thehackernews.com — 28.09.2026 22:18
- Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks — thehackernews.com — 28.09.2026 22:18