Security & AI news

macOS security updates · By FireAI Security & Research Team · Published

Apple fixes a CoreGraphics flaw in macOS Tahoe 26.7.1 and Sequoia 15.8.1 that it says was used in a targeted attack

Apple patched CVE-2026-86950, a CoreGraphics flaw reported by Meta, in macOS Tahoe 26.7.1 and Sequoia 15.8.1 and says it may have been exploited against specific people.

A shield over a laptop and the FireAI update rocket mascot, next to the words “Update to macOS 26.7.1: a flaw is fixed.”

Apple has fixed CVE-2026-86950, an out-of-bounds write in CoreGraphics reported by Meta's product security team, in macOS Tahoe 26.7.1 and macOS Sequoia 15.8.1, The Hacker News reported on 28 September. Apple says the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals. Opening a specially crafted file could allow arbitrary code execution.

Background

CoreGraphics is Apple's graphics framework, which processes images and documents in many apps. An out-of-bounds write is a memory error in which a program stores data outside the space set aside for it; in a file-parsing component it can be turned into code execution [1].

What the reports describe

Apple describes the fix as improved bounds checking. The company's wording, as quoted by TidBITS, is that it is aware of a report that the issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27. Fixes also shipped as iOS 26.7.1 and iPadOS 26.7.1 [1] [2].

The 26.7.1 and 15.8.1 releases follow the catch-up updates macOS Tahoe 26.7 and Sequoia 15.8. TidBITS advises that most people do not need to update within hours, but should do so within days, because publication of a fix speeds up work on exploits [2].

Meta's product security team reported the flaw, according to The Hacker News [1]. Apple describes the attack only as targeted; who was targeted, and how the flaw was reached, is not public.

Implications for Mac users

The exploitation Apple mentions concerns iOS, and Apple's wording does not say a Mac was attacked. The flaw exists in the macOS versions named above, so those Macs are exposed until updated. Neither report states whether macOS 27 is affected, or how many people were targeted [1] [2].

Recommendations

  1. Open System Settings › General › Software Update and install the latest version for your Mac within the next few days.
  2. Do not open unexpected image or document files from unknown senders while the update is pending.

Relevance to FireAI

A memory flaw in a system framework is fixed by Apple's update, and FireAI cannot patch it or stop a crafted file from being parsed. FireAI's part comes afterwards: code that runs on a Mac and tries to send data out has to make a connection, and FireAI asks about connections from apps that have no rule. The kill switch refuses new outside connections in one click if something seems wrong. Update macOS first.

Limitations

Apple gave no details on who was targeted, when exploitation began or what the attack delivered. The two outlets differ in what they say about CVE listings: The Hacker News gives the identifier, and TidBITS noted that release notes initially showed no published CVE entries [1] [2].

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. The Hacker News, 28 September 2026: Apple patches CoreGraphics flaw possibly exploited in targeted attacks
  2. TidBITS, 28 September 2026: Apple patches an exploited flaw alongside September operating system fixes